The record
Written from the 1 report below. Nothing here is unsourced.
- Security firm Zenity Labs disclosed a critical vulnerability, codenamed AgentForger, in OpenAI's ChatGPT Workspace Agent Builder that let a single phishing link create and deploy a rogue AI agent inside a victim's organization.
- The flaw was a cross-site request forgery that exploited URL parameters to automatically execute a malicious prompt in a logged-in user's session, creating an agent with the employee's access, approvals disabled, and a recurring schedule.
- The agent could then harvest documents, steal passwords, and impersonate the victim to send phishing links.
- OpenAI patched the issue as of June 8, 2026, following responsible disclosure.
What to watch next
- OpenAI is deprecating Agent Builder effective November 30, 2026, with users directed to the Agents SDK and Workspace Agents.
- Whether organizations audit existing workspace agents and connector approval settings for similar abuse.
- Further research from Zenity on exposed AI infrastructure like LiteLLM and Ollama being used for offensive operations.
Coverage1
1 report
English national1
All filed from India
Named United States · Agent Builder · ChatGPT Workspace Agents · Mike Takahashi · OpenAI · Zenity Labs
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
