← BACK TO FEED
TAG

openai security1 articles

One Phishing Link Was All It Took to Plant an Invisible AI Agent Inside Your Company

Zenity Labs discovered a critical vulnerability called "AgentForger" in OpenAI's ChatGPT Workspace Agents, which exploited a cross-site request forgery flaw in the Agent Builder to allow attackers to covertly create a fully autonomous AI agent inside a victim's organization with a single malicious link click. Once installed, the invisible agent could be remotely controlled via specially crafted emails, giving attackers access to connected apps, sensitive data, and the ability to impersonate the victim — all without triggering any security alerts. OpenAI acknowledged the flaw within one day of disclosure and patched it within three days.

25 Jul 2026