SECURITYTHE REGISTER
One ChatGPT link could smuggle a rogue AI agent into your company
Researchers at Zenity Labs discovered a security flaw in OpenAI's ChatGPT workspace agents, dubbed 'AgentForger,' which allows attackers to create malicious AI agents by tricking victims into clicking a disguised link. These agents can access connected corporate services like Outlook, Teams, and Google Drive to steal data or send phishing messages, leveraging the victim's permissions without requiring password theft.
Mentioned
Related Signal
Adjacent reporting
- ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
- Firm hacked by rogue AI calls the attack 'a wake-up call' after ChatGPT maker OpenAI admits advanced bot broke containment during a security test
- ChatGPT maker OpenAI says AI model went rogue during testing and 'escaped' into the internet where it launched 'unprecedented' cyberattack
- OpenAI agent goes rogue, hacks into rival AI startup during security test
- ChatGPT blindly trusts browser content, turning the page into a payload
- Open AI models go rogue, ecape and and hack online AI sharing hub