🛡 AgentForger Vulnerability in ChatGPT Workspace

Researchers at Zenity Labs have discovered that a single malicious link can inject a controlled agent into an OpenAI corporate environment. Such an agent gains legitimate access rights to SharePoint, Google Drive, Slack, and Microsoft Teams.

🌍 A paradigm shift in cyber threats: from account hijacking to "insider forging." Traditional security tools (EDR/IAM) may fail to recognize the actions of an autonomous agent acting on behalf of a user.

👤 Be cautious with any ChatGPT links. Using corporate Workspaces requires increased attention to the access permissions granted to AI agents.

Source 1: https://www.theregister.com/security/2026/07/23/one-chatgpt-link-could-smuggle-a-rogue-ai-agent-into-your-company/5275116