Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaw in ChatGPT Agents Allows Rogue AI Deployment

Critical Flaw in ChatGPT Agents Allows Rogue AI Deployment

Posted on July 24, 2026 By CWS

Cybersecurity experts have revealed a serious security gap in OpenAI’s ChatGPT Workspace Agents, termed as AgentForger, which could have been exploited through a single phishing link to create unauthorized AI agents within a company. Zenity Labs uncovered this flaw, leading to OpenAI addressing the issue by June 8, 2026, following a responsible disclosure.

Understanding the AgentForger Vulnerability

This vulnerability allowed attackers to misuse OpenAI’s ChatGPT Agent Builder, a tool for creating AI workflows, to set up AI agents with unauthorized access. The attack is initiated when an employee clicks on a seemingly harmless ChatGPT link, enabling the creation of an attacker-controlled AI agent within the organization. This is a cross-site request forgery (CSRF) issue where the AI agent is controlled by a malicious actor.

The Builder tool accepts initialization data through URL parameters, which include an agent template and a prompt for the Builder. When loaded, the initialization prompt is automatically executed, making it possible for attackers to inject commands directly through the URL. This allows the malicious prompt embedded in the URL to act as the first command executed by the Builder.

Exploitation and Attack Execution

The exploit is carried out when a logged-in ChatGPT user clicks on a phishing link containing a URL crafted to include the malicious prompt. This setup requires the victim to have access to Workspace Agents and at least one authorized connector, such as Outlook or Slack. The malicious URL leverages these integrations to execute commands within the organization’s trusted environment.

The rogue AI agent can perform various unauthorized actions including creating an agent from a template, attaching connectors without user consent, and running tasks on a schedule. It can also execute tasks from specific emails and report results back to the attacker, effectively becoming a persistent insider threat.

Implications and Future Outlook

Once the rogue agent is established, it can perform reconnaissance, harvest sensitive data, and even impersonate the victim to spread further phishing attempts. Zenity Labs highlighted that this vulnerability reflects a deeper trust issue within AI platforms, where malicious agents can operate unchecked once deployed.

This discovery follows previous revelations about vulnerabilities in AI infrastructure, underscoring the ongoing challenges in securing AI systems as they become increasingly integrated into organizational operations. OpenAI’s response and the planned deprecation of the Agent Builder in favor of a more secure Agents SDK by November 30, 2026, marks a significant step towards mitigating such risks.

As AI continues to evolve, the need for robust security measures to protect against sophisticated threats like AgentForger becomes imperative. Organizations must continuously assess and enhance their security protocols to safeguard against the potential misuse of AI technologies.

The Hacker News Tags:Agent Builder, Agent SDK, AgentForger, AI agents, AI infrastructure, AI security, autonomous AI, ChatGPT, CSRF, Cybersecurity, malicious prompt, OpenAI, Phishing, Workspace Agents, Zenity Labs

Post navigation

Previous Post: Apache Syncope Updates Address Critical Security Flaws
Next Post: JetBrains Resolves Critical IntelliJ and TeamCity Flaws

Related Posts

North Korean Operatives Exploit LinkedIn to Access Companies North Korean Operatives Exploit LinkedIn to Access Companies The Hacker News
Google AI “Big Sleep” Stops Exploitation of Critical SQLite Vulnerability Before Hackers Act Google AI “Big Sleep” Stops Exploitation of Critical SQLite Vulnerability Before Hackers Act The Hacker News
The ROI Problem in Attack Surface Management The ROI Problem in Attack Surface Management The Hacker News
Hackers Exploit Adform Script to Alter Crypto Wallets Hackers Exploit Adform Script to Alter Crypto Wallets The Hacker News
China’s Massistant Tool Secretly Extracts SMS, GPS Data, and Images From Confiscated Phones China’s Massistant Tool Secretly Extracts SMS, GPS Data, and Images From Confiscated Phones The Hacker News
Apple Patches CVE-2025-43300 Zero-Day in iOS, iPadOS, and macOS Exploited in Targeted Attacks Apple Patches CVE-2025-43300 Zero-Day in iOS, iPadOS, and macOS Exploited in Targeted Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Stealth Linux Rootkit Targets F5 BIG-IP Servers
  • PEEP Exploits Chrome and Edge for Host Command Execution
  • Bimbo Bakeries Hit by Oracle EBS Data Breach
  • Critical Security Updates: Chrome 0-Day and More
  • Switzerland to Test Open-Source Alternative to Microsoft 365

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Stealth Linux Rootkit Targets F5 BIG-IP Servers
  • PEEP Exploits Chrome and Edge for Host Command Execution
  • Bimbo Bakeries Hit by Oracle EBS Data Breach
  • Critical Security Updates: Chrome 0-Day and More
  • Switzerland to Test Open-Source Alternative to Microsoft 365

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark