security

Researchers say OpenAI flaw let phishing bait create an autonomous corporate mole armed with employee access

One click on what looked like an ordinary ChatGPT link could plant an attacker-controlled AI agent inside a company's ChatGPT workspace, according to researchers who uncovered a flaw in OpenAI's workspace agents.Security firm Zenity Labs has dubbed the bug "AgentForger," saying its proof-of-concept showed it was possible to silently create, configure, publish, and schedule a malicious workspace agent inside a victim's ChatGPT account.The technique depended on the victim belonging to a workspace where agents were enabled and having permission to create them. Any connected apps and actions would also have to be allowed by the organization's administrators.

Rather than stealing passwords or browser sessions, the technique effectively tricked ChatGPT into building an autonomous assistant that could act through the employee's connected accounts and permissions.

If the victim had already connected services such as Outlook, Teams, Slack, SharePoint, or Google Drive, and the workspace allowed the relevant actions, Zenity says the agent could use them too. According to Zenity, that meant it could rummage through corporate data, send messages as the employee, and continue running long after the original phishing email had done its job.The weak spot was ChatGPT's agent builder, the feature used to spin up AI assistants that can work across email, chat, calendars, and other business apps. Zenity found it would accept instructions embedded inside what looked like an ordinary ChatGPT link. One click later, Zenity says, the builder got to work on the attacker's behalf, wiring up the victim's existing connectors, turning off approval prompts, publishing the new agent, and setting it loose on a schedule.From there, the researchers turned the agent into what amounted to a corporate mole. Instead of reaching out to conventional command-and-control infrastructure, it simply checked the victim's inbox for emails from the attacker with "TASK" in the subject line. Each message became a new assignment, whether that meant searching company files, collecting sensitive documents, or sending the results back by email.