AI Agent · OpenAI · GPT · ChatGPT · Google · The Register
Zenity found it would accept instructions embedded inside what looked like an ordinary ChatGPT link
Compiled by KHAO Editorial — aggregated from 2 sources. See llms.txt for citation guidance.
◎ Multiple-sources
From there, the researchers turned the agent into what amounted to a corporate mole.
Key facts
- This isn't a forged request, it's a forged insider," Michael Bargury, co-founder and CTO of Zenity, told The Register
- Zenity reported the issue to OpenAI through Bugcrowd on June 4
- Instead of reaching out to conventional command-and-control infrastructure, it simply checked the victim's inbox for emails from the attacker with "TASK" in the subject line
- Researchers say OpenAI flaw let phishing bait create an autonomous corporate mole armed with employee access
Summary
Researchers say OpenAI flaw let phishing bait create an autonomous corporate mole armed with employee access. One click on what looked like an ordinary ChatGPT link could plant an attacker-controlled AI agent inside a company's ChatGPT workspace, according to researchers who uncovered a flaw in OpenAI's workspace agents. Security firm Zenity Labs has dubbed the bug "AgentForger," saying its proof-of-concept showed it was possible to silently create, configure, publish, and schedule a malicious workspace agent inside a victim's ChatGPT account. The technique depended on the victim belonging to a workspace where agents were enabled and having permission to create them. Rather than stealing passwords or browser sessions, the technique effectively tricked ChatGPT into building an autonomous assistant that could act through the employee's connected accounts and permissions.