ChatGPT Workspace Agents Vulnerability Lets Attackers Deploy Persistent AI Insiders
Event summary
- Zenity Labs discovered 'AgentForger,' a vulnerability in OpenAI’s ChatGPT Workspace Agents that allowed attackers to deploy autonomous AI agents inside victim organizations with one phishing link click.
- The flaw exploited an overpermissive parameter in ChatGPT's Agent Builder, enabling unauthorized agent creation and deployment without user confirmation.
- AgentForger could exfiltrate sensitive data, harvest credentials, impersonate employees, and launch internal phishing campaigns, creating persistent threats.
- OpenAI fixed the vulnerability within four days of Zenity Labs' responsible disclosure on June 4, 2026.
The big picture
AgentForger highlights the emerging risks of autonomous AI agents in enterprise environments, where implementation flaws can lead to persistent insider threats. As AI agents gain more autonomy across critical applications, traditional security tools designed for user and endpoint monitoring become insufficient. This vulnerability underscores the need for agent-centric security frameworks that address the unique trust dynamics of autonomous systems operating with legitimate credentials.
What we're watching
- AI Agent Trust
- How the industry will adapt security controls to monitor autonomous agents operating under legitimate user identities.
- Enterprise Adoption
- Whether organizations will slow AI agent integration pending better governance frameworks for agent behavior and access.
- Vulnerability Response
- The pace at which other AI platforms implement similar fixes to prevent comparable agent trust failures.
Related topics
