Experts warn that ChatGPT’s Workspace Agent Builder can be hijacked to create malicious AI workers



  • Zenity Labs found AgentForger, a flaw in OpenAI’s ChatGPT Agent Builder
  • Malicious links could instantly deploy malicious agents that leak sensitive data without prompting from the user.
  • OpenAI fixed the issue by removing the risky URL parameter; no abuse detected

AI agents are useful for responding to customer emails or tracking reports of recently published security vulnerabilities. But what if they go rogue and attack the very company they are supposed to support?

Security researchers at Zenity Labs have found a way for cybercriminals to trick people into deploying such agents in their own technology stack. Since all it takes is a single click, the disruptive potential of these attacks is arguably significantly greater than anything else a phishing attack can do.

Leave a Comment

Your email address will not be published. Required fields are marked *