Experts warn ChatGPT’s Workspace Agent Builder can be hijacked to create malicious AI workers


  • Zenity Labs found AgentForger, a bug in OpenAI’s ChatGPT Agent Builder
  • Malicious links can instantly deploy rogue agents that exfiltrate sensitive data without user notification
  • OpenAI fixed the problem by removing the dodgy URL parameter; no abuse detected

AI agents are handy for answering customer emails or tracking reports for newly released security vulnerabilities. But what if they become unscrupulous and turn on the company they are supposed to support?

Security researchers from Zenity Labs have found a way for cybercriminals to trick people into inserting such agents into their own tech stack. Since all it takes is a single click, the disruptive potential of these attacks is arguably significantly greater than anything a phishing attack could do.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top