Back Feeds.4Sysops AgentForger allowed attackers to deploy malicious AI agents within corporate ChatGPT workspaces
Researchers recently identified a vulnerability dubbed "AgentForger" that allowed attackers to deploy malicious, autonomous AI agents within corporate ChatGPT workspaces. By embedding specific instructions into a seemingly benign link, an attacker could trick a user into creating an assistant that inherits the victim's permissions. Once active, this agent could operate across connected business applications like Slack, Outlook, and Google Drive without further user interaction. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
