hacker-news · Crawled Jul 24, 2026

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

1 IoCs 2 CVEs
Read original article ↗

AI Summary

A critical vulnerability named AgentForger in OpenAI's ChatGPT Workspace Agents could allow attackers to deploy rogue AI agents via a phishing link. The flaw, a cross-site request forgery (CSRF), enables automatic creation and execution of malicious agents within an authenticated user's session without further interaction. These agents can persist, execute tasks from emails, access enterprise data, and send phishing messages, effectively becoming autonomous insiders.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 1 extracted

Type Value Detail
Domain chatgpt[.]com Details →

MITRE ATT&CK TTPs 5 techniques