hacker-news · Crawled Jul 24, 2026
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
1 IoCs 2 CVEs
Read original article ↗
AI Summary
A critical vulnerability named AgentForger in OpenAI's ChatGPT Workspace Agents could allow attackers to deploy rogue AI agents via a phishing link. The flaw, a cross-site request forgery (CSRF), enables automatic creation and execution of malicious agents within an authenticated user's session without further interaction. These agents can persist, execute tasks from emails, access enterprise data, and send phishing messages, effectively becoming autonomous insiders.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | chatgpt[.]com | Details → |