OpenAI Fixes Flaw That Let a Single Link Plant a Rogue AI Agent Inside Your Company

A serious security hole in OpenAI’s ChatGPT Workspace Agents could have let attackers plant a fully autonomous AI agent inside a victim’s organization with just one phishing link. Security firm Zenity Labs, which discovered the bug and dubbed it AgentForger, reported that the vulnerability was patched by OpenAI on June 8, 2026. The attack exploited the platform’s Agent Builder — a drag-and-drop tool for creating multi-step workflows — which accepted instructions directly through URL parameters.
Here’s how it worked: An employee logged into ChatGPT would click a seemingly harmless link. That link automatically opened the Agent Builder in their authenticated session, submitted a malicious prompt, and instructed the Builder to create an agent using a chief-of-staff template. The prompt then attached all available connectors (like Outlook, Gmail, Slack, or Teams), set them to “Never ask” so no approvals were needed, published the agent, and scheduled it to run every hour. The agent would then wait for emails from a specific address with “TASK” in the subject line, execute those tasks, and email the results back to the attacker.
Once active, the rogue agent could read sensitive documents, steal passwords from Slack messages, and even impersonate the victim to send phishing links on Teams — potentially leading to credential theft and business email compromise. Zenity’s Mike Takahashi noted that the attacker didn’t need the victim to click again or keep the browser tab open. “Once the agent is published and scheduled, the attacker can keep sending it assignments through the victim’s mailbox,” he said. The core issue, Zenity explained, was a trust failure: the platform assumed the user intentionally created and approved every agent action.
Source: The Hackers News
dArt Studio installs AI for local businesses in Broward & Palm Beach County, FL. We reply within 1 business hour.