🛡 AgentForger Vulnerability in ChatGPT Workspace
Researchers at Zenity Labs have discovered that a single malicious link can inject a controlled agent into an OpenAI corporate environment. Such an agent gains legitimate access rights to SharePoint, Google Drive, Slack, and Microsoft Teams.
🌍 A paradigm shift in cyber threats: from account hijacking to "insider forging." Traditional security tools (EDR/IAM) may fail to recognize the actions of an autonomous agent acting on behalf of a user.
👤 Be cautious with any ChatGPT links. Using corporate Workspaces requires increased attention to the access permissions granted to AI agents.
