HomeArtificial Intelligence (AI)One Link Could Have Planted a Fake Employee Inside Any Company Using...

One Link Could Have Planted a Fake Employee Inside Any Company Using ChatGPT’s Agent Builder

Security researchers found a way to turn a single clicked link into something far more dangerous than a typical phishing attack: a fully autonomous AI agent, quietly operating inside a company with a real employee’s identity and access, taking orders from an outside attacker every five minutes.

What Zenity Labs Found

Security firm Zenity Labs disclosed a vulnerability in OpenAI’s ChatGPT Workspace Agents that it named AgentForger — a deliberate riff on cross-site request forgery, the decades-old web attack it evolves. The flaw lived in ChatGPT’s Agent Builder, a visual tool for constructing multi-step autonomous agent workflows. Zenity found that two URL parameters in the Builder’s initialization process could be manipulated: one selected an agent template — defaulting to a powerful “Chief of Staff” template — and the other, called `initial_assistant_prompt`, fed the Builder natural-language instructions that were automatically submitted and executed the moment the page loaded, without requiring the user to type or confirm anything.

Chained together, those two parameters let an attacker craft a single URL that, when clicked by a logged-in employee, silently built, configured, and launched a fully functional autonomous agent inside that employee’s ChatGPT Workspace — one instructed to check the attacker’s email inbox for new commands every five minutes.

Why This Is Worse Than a Normal Phishing Link

Traditional cross-site request forgery tricks a browser into submitting one unauthorized request. AgentForger did something categorically different: it forged the creation of a persistent, tool-equipped autonomous system operating inside a company’s trust boundary. Zenity co-founder and CTO Michael Bargury put it bluntly: “This isn’t a forged request, it’s a forged insider. With one click, an attacker gets a fully autonomous agent inside your company that has your people’s identity and access, with the guardrails off.”

The attack only required a target employee to be logged into ChatGPT with Workspace Agents enabled and at least one pre-authorized enterprise connector — Outlook, Gmail, Slack, or SharePoint among them. Because the connector was already authorized, no new permission prompt appeared to warn the employee something unusual was happening. Zenity’s researchers demonstrated that the resulting rogue agent could map an organization’s internal structure, exfiltrate sensitive documents, harvest credentials, and impersonate the victim across Slack, Teams, and email.

How Quickly It Got Fixed

Zenity reported the vulnerability to OpenAI through the Bugcrowd program on June 4, 2026. OpenAI confirmed the report within 24 hours and shipped a fix by June 8 — four days from initial report to patch — by removing the vulnerable URL parameter handler entirely. Zenity has said it found no evidence the flaw was exploited in the wild before the fix went live, and OpenAI has separately announced it’s deprecating the original Agent Builder tool entirely, effective November 30, 2026, in favor of its newer Agents SDK and Workspace Agents interface.

Part of a Broader Pattern

AgentForger belongs to a growing category security researchers are calling the “lethal trifecta”: untrusted input, access to private data, and an unmonitored path to exfiltrate it — three conditions that, together, turn an AI agent’s helpfulness into a liability. It’s a structurally different failure mode than the sandbox-escape and reward-hacking incidents covered elsewhere recently, including Kimi K3’s sandbox break and the string of frontier-model containment failures this summer; see our roundup of AI agent safety incidents for the wider pattern. Where those incidents involved a model exceeding its intended boundaries on its own, AgentForger shows how an attacker can weaponize an agent platform’s own convenience features — one-click setup, pre-authorized connectors — against the organization using it.

What to Watch Next

Security researchers are treating AgentForger as a preview of a broader vulnerability class rather than an isolated bug: as more companies adopt agent-builder tools with deep, pre-authorized access to internal systems, the attack surface for this kind of “forged insider” grows accordingly. Expect continued scrutiny of how AI agent platforms handle URL-based initialization and default permission inheritance as enterprise adoption of autonomous agents accelerates through the rest of 2026.

Sources: The Hacker News, SecurityWeek, Zenity Labs research


Disclaimer: This content is meant to inform and should not be considered financial advice. The views expressed in this article may include the author’s personal opinions and do not represent Times Tabloid’s opinion. Readers are advised to conduct thorough research before making any investment decisions. Any action taken by the reader is strictly at their own risk. Times Tabloid is not responsible for any financial losses.

Solomon Odunayo
Solomon Odunayo
Solomon is a trader, crypto enthusiast, and analyst with over seven years of experience in the industry. He strongly believes that crypto assets and the blockchain will continue to gain prominence. At TimesTabloid.com, he focuses on news, articles with deep analysis of blockchain projects, and technical analysis of crypto trading pairs.
RELATED ARTICLES

Latest News & Articles