Threat · curated 23 Jul 2026
One ChatGPT link could smuggle a rogue AI agent into your company
First reported theregister.com
Coverage timeline
Why it matters
AgentForger shows a single phishing click can forge an autonomous insider agent operating with a real employee's identity and access and guardrails disabled, a threat class existing security controls were not built to detect.
Zenity Labs disclosed "AgentForger," a flaw in OpenAI's ChatGPT workspace agent builder that let a single crafted ChatGPT link embed instructions which silently create, configure, publish, and schedule a malicious autonomous agent inside a victim's workspace. Their proof-of-concept showed the forged agent could abuse the employee's connected apps (Outlook, Teams, Slack, SharePoint, Google Drive) to exfiltrate corporate data, using inbox emails with "TASK" in the subject as a covert command-and-control channel.