
One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes
Quick Answer
Zenity Labs discovered a vulnerability named 'AgentForger' in OpenAI's Workspace Agents, allowing attackers to create rogue AI agents that autonomously check for commands every five minutes, leveraging existing app permissions without user consent.
Quick Take
This new attack method represents an evolution of classic CSRF attacks, posing significant risks to organizational security.
Key Points
- AgentForger allows attackers to forge an entire AI agent instead of a single request.
- The attack requires the victim to be logged into ChatGPT and have authorized connectors.
- Agents can execute commands every five minutes, accessing sensitive company data.
- The vulnerability bypasses approval steps, leveraging existing permissions for malicious tasks.
- Attackers can use the agent to send phishing messages and execute unauthorized actions.
Source Excerpt
Zenity Labs uncovered "AgentForger," a vulnerability in OpenAI's Agent Builder that let a single manipulated ChatGPT link create an autonomous agent on an employee's behalf. The agent inherited the victim's identity and access rights, bypassed approval requirements through the malicious prompt, and pulled new instructions from the attacker's inbox every five minutes.
Want this in your inbox every morning?
Daily brief at your local 8am — bilingual EN/中文, free.
More from The Decoder
See more →
An AI model programmed nonstop for 19 days on a single MirrorCode task that cost $2,600 to run
Epoch AI's MirrorCode benchmark reveals Claude Opus 4.7 as the leader with a 56% solve rate, reconstructing a 16,000-line toolkit in 14 hours. Despite this, all models tested struggle with the most complex tasks, highlighting limitations in current AI capabilities. The single task consumed $2,600 over 19 days, raising questions about cost-effectiveness in AI development.

