One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes
OpenAI Workspace Agents 漏洞:一个 ChatGPT 链接即可创建恶意 AI 智能体
Zenity Labs found a vulnerability in OpenAI Workspace Agents called AgentForger. A single manipulated ChatGPT link could auto-create and publish an AI agent under the victim's account, reusing their existing app permissions for Outlook, Slack, and more. The agent then checked the attacker's inbox every five minutes for new orders, with no approval prompts shown. OpenAI fixed it in four days, but Zenity argues the real problem is deeper: traditional security tools aren't built to spot autonomous agents operating under legitimate user identities.
Why it matters: AgentForger isn't a conceptual warning—it's a disclosed chain with concrete timing (every 5 min callback) and OpenAI confirmed + patched it. Workspace Agents are rolling out now, so a trust-model bypass that reuses existing app permissions hits enterprise security teams exactl...