Dossier
AgentForger
Coverage of AgentForger in the Nexus archive.
- One ChatGPT link could smuggle a rogue AI agent into your company
Researchers at Zenity Labs discovered a security flaw in OpenAI's ChatGPT workspace agents, dubbed 'AgentForger,' which allows attackers to create malicious AI agents by tricking victims into clicking a disguised link. These agents can access connected corporate services like Outlook, Teams, and Google Drive to steal data or send phishing messages, leveraging the victim's permissions without requiring password theft.