AgentForger Vulnerability Allows Malicious AI Deployment in Corporate ChatGPT Workspaces

AgentForger Vulnerability Allows Malicious AI Deployment in Corporate ChatGPT Workspaces

First seen 23 Jul 2026, 14:24 UTC TheregisterFeeds.4SysopsMorningstarcts.businesswire.com 89% similarity 64.5

Article Content

Browse articles
ThreatCluster

A newly discovered vulnerability named 'AgentForger' permits attackers to deploy malicious AI agents within corporate ChatGPT workspaces. By embedding instructions in a seemingly benign link, an attacker can trick users into creating an AI assistant that inherits their permissions. This agent can operate across connected applications like Slack, Outlook, and Google Drive without further user interaction. The flaw was identified by Zenity Labs, which demonstrated that the malicious agent could access sensitive corporate data and send messages as the victim. The vulnerability highlights a significant trust failure in AI agent management systems. Organizations using ChatGPT are at risk if their workspaces allow agent creation and connected apps. The researchers emphasized that existing security measures are inadequate to detect such insider threats. No specific CVEs have been reported yet, but the implications are severe for corporate security.

Key Points: • The 'AgentForger' vulnerability allows attackers to create malicious AI agents in ChatGPT workspaces. • Malicious agents can operate across connected applications without further user interaction. • Existing security controls are insufficient to detect this type of insider threat.

ThreatCluster AI

Timeline

2026-07-23
AgentForger vulnerability disclosed
Zenity Labs revealed the AgentForger vulnerability, enabling attackers to deploy malicious AI agents in corporate ChatGPT workspaces.
Theregister
2026-07-23
Proof-of-concept demonstration
Zenity Labs demonstrated how a single click on a malicious link could create an autonomous agent with the victim's permissions.
Feeds.4Sysops

Community

Browse all →