Threat · curated 23 Jul 2026
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
First reported · updated · 3 reports zenity.io
Coverage timeline
Why it matters
AgentForger shows that a phishing click can forge a fully autonomous insider agent with an employee's access and guardrails off, a class of agent-trust abuse that existing security controls were not built to detect.
Zenity Labs disclosed "AgentForger," a flaw in OpenAI's ChatGPT workspace agent builder that let a single crafted ChatGPT link silently create, configure, publish, and schedule an attacker-controlled autonomous agent inside a victim's workspace. The proof-of-concept agent inherited the employee's identity and connected apps (Outlook, Teams, Slack, SharePoint, Google Drive), disabled approval prompts, and used inbox messages tagged "TASK" as a covert command-and-control channel to search and exfiltrate corporate data.