Threat · curated 23 Jul 2026

One ChatGPT link could smuggle a rogue AI agent into your company

Coverage timeline

23 Jul 2026theregister.com

Why it matters

AgentForger shows a single phishing click can forge an autonomous insider agent operating with a real employee's identity and access and guardrails disabled, a threat class existing security controls were not built to detect.

Zenity Labs disclosed "AgentForger," a flaw in OpenAI's ChatGPT workspace agent builder that let a single crafted ChatGPT link embed instructions which silently create, configure, publish, and schedule a malicious autonomous agent inside a victim's workspace. Their proof-of-concept showed the forged agent could abuse the employee's connected apps (Outlook, Teams, Slack, SharePoint, Google Drive) to exfiltrate corporate data, using inbox emails with "TASK" in the subject as a covert command-and-control channel.