🔴 Critical | Source: The Hacker News
A critical vulnerability dubbed AgentForger, discovered by Zenity Labs in OpenAI’s ChatGPT Workspace Agents, could have allowed an attacker to silently create, authorise, and deploy a rogue AI agent inside a victim’s organisation using nothing more than a phishing link. The flaw required no elevated access beyond tricking a user into clicking a malicious URL, giving attackers a stealthy foothold within enterprise AI workflows. OpenAI patched the issue on 8 June 2026.
Security Architect’s Take: Review your organisation’s ChatGPT Enterprise and Workspace Agent permissions to ensure least-privilege principles are enforced, and implement phishing-resistant MFA and user awareness training specifically covering AI agent authorisation prompts — users should be suspicious of any unexpected agent deployment requests regardless of how legitimate they appear.
Original advisory: ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link