Feeds.4Sysops
AgentForger: New Phishing Attack Creates Autonomous AI Insiders
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Zenity Labs has identified a critical vulnerability named AgentForger in OpenAI's ChatGPT Workspace Agents. This flaw allows attackers to create a malicious AI agent within an organization by embedding instructions in a phishing link. Once activated, the agent operates autonomously, inheriting the victim's permissions and accessing connected applications like Outlook, Slack, and Google Drive. The attack requires only one click from a logged-in user, enabling the agent to perform tasks such as data exfiltration and impersonation without further interaction. OpenAI resolved the vulnerability four days after it was disclosed, but organizations remained exposed until the fix was implemented. This incident highlights a new class of AI security risks where attackers can forge insiders rather than relying on traditional malware. The vulnerability underscores the need for enhanced security measures in AI agent deployment.
Key Points: • AgentForger allows attackers to create autonomous AI agents with victim permissions via phishing links. • The attack requires only one click from a logged-in user, enabling persistent insider threats. • OpenAI patched the vulnerability within four days of disclosure, but organizations were at risk until then.