News
AI SHIFT:

OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider Risk

Newsroom brief

SecurityWeek reported that OpenAI fixed the AgentForger flaw in ChatGPT Workspace Agents after Zenity Labs showed how a phishing link could create a hidden autonomous agent with access to already-authorised connectors.

Verified against source materialEdited by SendTech Times Cybersecurity Desk
OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider Risk
Image source: SecurityWeek

A hidden AI agent inside a company account changes the risk profile of ordinary phishing because the compromised object is not just a browser session or password.

SecurityWeek reported that OpenAI fixed a ChatGPT Workspace Agents flaw after Zenity Labs showed how a crafted link could create an autonomous agent with access to already-authorised connectors.

Zenity Labs named the flaw AgentForger and classified it as a tailored cross-site request forgery issue in ChatGPT's Agent Builder.

The exposure depended on a victim employee being logged into ChatGPT, having Workspace Agents access and already-authorised connectors such as Gmail or Outlook, so the attack path did not require a new OAuth consent screen.

The affected feature sits in ChatGPT Workspace Agents, where business accounts can connect productivity apps before an agent acts across the workspace.

Agent Builder Became The Trust Boundary

The agent-creation step gave the bug its enterprise weight.

Zenity's disclosure described parameters in an initialisation URL as a way to preconfigure the build process and supply the first instructions the Builder acted on.

The resulting agent could be made difficult for the organisation to see and could receive later directions through connected apps.

Zenity's disclosure framed that as an autonomous system with tools, approvals, a schedule and access to already-authorised connectors, which moves the exposure beyond conventional CSRF.

Security teams normally treat CSRF as an unintended action performed through a user's browser.

AgentForger pushed that action into agent creation: the system that was created could keep operating after the original click, use the victim's authorised connectors and return data through the connected workflow.

OpenAI Fixed The Bug In Three Days

SecurityWeek reported that Zenity disclosed AgentForger on June 4 and OpenAI fixed it on June 8.

The same account put OpenAI's acceptance of the findings within a day and the repair window at three days.

The short repair window narrows the immediate product exposure, but the incident still gives enterprise AI buyers a clearer failure mode to test.

Admin controls, connector permissions, approval prompts and agent visibility all become security controls when an AI workspace can act across email or productivity systems.

The product consequence is specific: a workspace agent inherits trust from the user and the connector before it performs work.

If an attacker can influence the build process, the organisation must detect not only suspicious logins or malicious files, but also unauthorised agent creation, hidden schedules and unexpected connector use.

Connector Access Raises The Response Burden

Zenity's account of the flaw included possible abuse paths such as reconnaissance, sensitive-data discovery, credential harvesting, internal phishing, impersonation and business email compromise.

Those outcomes depended on the permissions and connectors already available to the victim account.

The remediation lesson is not to publish more detailed attack steps.

Security teams need evidence that agent builders, connector grants and scheduled actions are visible in logs, can be reviewed by administrators and can be revoked when a phished user has authorised access to sensitive apps.

OpenAI's fix closes the disclosed AgentForger path, while the public record does not show whether affected Workspace customers received customer-specific exposure findings or whether similar agent-builder flows have been audited across other enterprise AI tools.

Share this article
inXf

Related articles

More
Neo Raises $100M To Control Enterprise AI Software Actions
Cybersecurity

Neo Raises $100M To Control Enterprise AI Software Actions

SecurityWeek reported that Neo emerged from stealth with $100 million for a platform that governs AI agents, MCP servers and software actions across enterprise systems.

AI Coding Agents Face Sandbox-Escape Findings Across Four Tools
Cybersecurity

AI Coding Agents Face Sandbox-Escape Findings Across Four Tools

BleepingComputer reported that Pillar Security reproduced sandbox-escape paths in Cursor, OpenAI Codex, Gemini CLI and Google Antigravity, shifting attention from agent containment to trusted developer tools around the workspace.

Injective SDK npm Compromise Exposes Wallet-Key Theft Risk
Cybersecurity

Injective SDK npm Compromise Exposes Wallet-Key Theft Risk

Socket, Ox Security and StepSecurity said they detected wallet-stealing code in @injectivelabs/sdk-ts npm package version 1.20.21 after an Injective Labs contributor account was compromised. Socket said the malicious release was downloaded 310 times before deprecation, while Ox Security counted 87 direct dependencies and described a six-figure cumulative download count across dependent packages.

Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery Chain
Cybersecurity

Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery Chain

DeveloperTech's article on Arctic Wolf Labs research describes a fake-repository campaign that used polished GitHub project pages as a delivery route for BoryptGrab malware. The case makes artifact provenance and workstation controls more important than visual trust in repository pages.

CISA Tightens GitHub Controls After May AWS Key Leak
Cybersecurity

CISA Tightens GitHub Controls After May AWS Key Leak

CISA said privileged AWS GovCloud keys from a contractor appeared in a public GitHub repository in May, prompting secret rotation, repository monitoring and new incident playbooks. Logs showed no customer or mission data exposure, while the contractor, repository, exposure window and exact AWS permissions remain outside the public account.

Sysdig Says AI Ransomware Still Needed Human Setup
Cybersecurity

Sysdig Says AI Ransomware Still Needed Human Setup

Sysdig described JadePuffer as agentic ransomware, but Michael Clark said a human still chose the victim, provisioned infrastructure and supplied database credentials before the AI agent executed the attack.

Keep Reading

More Stories

Latest
BitMEX Wind-Down Ends A Perpetual-Swap Pioneer After 11 YearsCrypto/Web3Jul 23, 2026BitMEX Wind-Down Ends A Perpetual-Swap Pioneer After 11 YearsCoinDesk reported that BitMEX will shut down operations on September 23, 2026, with new registrations halted, user withdrawals urged and remaining contracts set for forced closure before the final deadline.South Korea Tests AI-RAN And 5G For Industrial Robot NetworksTelco & ConnectivityJul 23, 2026South Korea Tests AI-RAN And 5G For Industrial Robot NetworksRCR Wireless reports that South Korea has put KRW17.2 billion ($11.6 million) behind SK Telecom and KT-led AI-RAN trials for shipyards, factories and robot workloads.CXMT Pre-IPO Contract Tests Crypto Price Discovery For China Chip ListingCapital & PolicyJul 23, 2026CXMT Pre-IPO Contract Tests Crypto Price Discovery For China Chip ListingA Hyperliquid contract linked to ChangXin Memory Technologies is pricing the Chinese memory-chip maker far above its planned Shanghai offer before a restricted STAR market debut.Treasury Warning Sends Moonshot Distillation Claim Toward AI SanctionsCapital & PolicyJul 23, 2026Treasury Warning Sends Moonshot Distillation Claim Toward AI SanctionsA U.S. Treasury warning over alleged AI model distillation brings Moonshot’s Kimi K3 release into a policy test for Chinese open-weight models, Nvidia GB300 access and export-control enforcement.Google Keeps TPU Priority On AGI As Cloud Demand Strains CapacityAIJul 23, 2026Google Keeps TPU Priority On AGI As Cloud Demand Strains CapacityAlphabet told investors that its first compute-allocation priority is frontier AGI development, while Google Cloud demand and AI infrastructure spending are pushing the company to use third-party capacity as a bridge.White House Presses PJM Grid Reform As AI Power Demand RisesCloud & Data CentersJul 23, 2026White House Presses PJM Grid Reform As AI Power Demand RisesThe White House warned PJM Interconnection to reform its board governance and stakeholder process as AI data centres and other large loads intensify disputes over grid reliability, electricity prices and infrastructure cost allocation.OpenAI Presence Makes Enterprise AI Agents A Consulting SaleAIJul 22, 2026OpenAI Presence Makes Enterprise AI Agents A Consulting SaleOpenAI’s Presence service is available to eligible enterprise customers through deployed engineers, not as a self-service product, with pricing still scoped individually.Kratos Takedown Leaves Microsoft 365 Session-Theft Risk UnfinishedCybersecurityJul 22, 2026Kratos Takedown Leaves Microsoft 365 Session-Theft Risk UnfinishedGerman and US law enforcement took more than 200 Kratos phishing-kit servers offline, but investigators still tie the service to roughly 1,800 customers and session-theft attacks against Microsoft 365.Augustus Raises $180m For Dollar Rails Across Emerging-Market FintechsFintech & Digital PaymentsJul 22, 2026Augustus Raises $180m For Dollar Rails Across Emerging-Market FintechsAugustus announced a $180 million Series B at a $1 billion valuation, with funding aimed at dollar accounts, payment rails and stablecoin-enabled banking for fintechs and banks across Latin America, Southeast Asia, the Middle East and Africa.China IPv6 Plan Advances Single-Stack Network And Metadata ControlsTelco & ConnectivityJul 22, 2026China IPv6 Plan Advances Single-Stack Network And Metadata ControlsChina is setting 2027 and 2030 IPv6 targets while pushing IPv6+ work that could give carriers more metadata about traffic, raising policy questions for network and cloud buyers outside China.Prysmian Signs $6.29bn Molex Cable Deal For AI Data CentresCloud & Data CentersJul 22, 2026Prysmian Signs $6.29bn Molex Cable Deal For AI Data CentresData Center Dynamics reported that Prysmian’s €5.5 billion Molex agreement includes a €550 million upfront payment and a capacity plan to more than double US fibre output.Spain AI Campus Seeks 300 MW With On-Site Power PlanCloud & Data CentersJul 22, 2026Spain AI Campus Seeks 300 MW With On-Site Power PlanData Center Knowledge reported that EdgeMode, BlackBerry AIF and Mora are seeking regional support for DC MALPICA, a proposed €3 billion ($3.4 billion), 300 MW AI campus whose power model remains partly undisclosed.