VMTech
Discuss a project

AgentForger: one phishing link could launch a malicious AI agent in ChatGPT Workspace

AgentForger: one phishing link could launch a malicious AI agent in ChatGPT Workspace

Colleagues, I’d like to highlight a cybersecurity and AI incident.

Zenity Labs disclosed AgentForger, a vulnerability in ChatGPT Workspace Agents. A single phishing link could open Builder in the victim’s session and automatically pass a malicious prompt via URL.

With corporate connectors enabled, the agent could be created, published, and run without further confirmation.

The risk was significant: access to email and business services, data collection, and sending messages on behalf of the victim.

OpenAI fixed the issue on 8 June 2026.

Why this matters: AI agent permissions must be governed as strictly as employee access.

Are you reviewing your AI agent access policy?
#cybersecurity #AI #OpenAI #phishing

Open analytics
On the site 9 views
min read 1 24.07.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

AgentForger: one phishing link could launch a malicious AI agent in ChatGPT Workspace

Open the post on Instagram ↗