Researchers from Zenity Labs have discovered a critical vulnerability called AgentForger in the OpenAI ChatGPT Workspace agent builder, which allows attackers to inject controlled autonomous agents into a corporate environment using just a single malicious link.

What Happened
During the investigation of the AgentForger vulnerability, it was found that sending a specially crafted link to a user allows for the creation of a controlled autonomous agent within ChatGPT Workspace. The resulting agent inherits the employee's legitimate access rights to corporate services, including SharePoint, Google Drive, Slack, and Microsoft Teams, providing the ability to covertly steal data or intercept communications.
Context
The problem lies in the fact that modern security systems, such as EDR and IAM, are oriented toward detecting account breaches or system call anomalies. However, in this case, the actions of the malicious agent appear as legitimate activity from an authorized user utilizing their standard permissions to work within the corporate environment.
Why It Matters for the Industry
The discovery of AgentForger marks a paradigm shift in cyber threats: moving from classic credential theft to the creation of "fake insiders." This creates new demand for Agent Governance tools and specialized solutions for monitoring AI agent behavior (Agent Observability & Control), and requires the transformation of EDR/XDR systems to analyze the action logic of autonomous systems.
Why It Matters for Users
Corporate users should exercise increased caution when interacting with any external links within ChatGPT. Organizations are recommended to immediately conduct an audit of the permissions granted to AI agents in Workspace environments and review permission policies to prevent unauthorized access to critical data.
What Is Not Yet Known / Limitations
No significant technical disagreements regarding the assessment of the vulnerability mechanism were identified; however, there is a difference in expert focus, ranging from the purely technical difficulty of detection to the assessment of market opportunities for new security products.
Sources
Author
Look at AI, Editorial Staff
