AgentForger: The New Corporate Mole
A now-patched flaw in OpenAI's platform allowed attackers to deploy autonomous, malicious agents via a single malicious link.
The evolution of AI assistants from simple chatbots into active, permission-based agents has created a novel vector for corporate espionage. Researchers at Zenity Labs recently identified a vulnerability, dubbed AgentForger, that allowed an attacker to bypass traditional defenses by essentially forcing a user to build their own digital saboteur.
The Anatomy of an Agent Hijack
The technique relied on an inherent flaw in the ChatGPT agent builder, which allowed malicious instructions to be embedded within standard URLs. When an unsuspecting user clicked such a link, the platform would automatically trigger the creation and configuration of an agent under the attacker’s control. Crucially, the process could be automated to disable security prompts and publish the agent without the user’s explicit intervention.
By leveraging the existing connectors already established by the victim, the malicious agent gained the ability to interact with critical internal tools. This includes access to services like Outlook, Teams, Slack, and Google Drive. Because the agent operated under the identity and permission sets of the authorized employee, it effectively bypassed standard access controls.
Operating as an Insider
Once deployed, the agent functioned as an autonomous corporate mole. Instead of using traditional command-and-control servers, it monitored the victim’s inbox for specific commands. Any email containing the word TASK in the subject line served as a new directive, allowing the agent to exfiltrate sensitive files, harvest API keys, or conduct internal phishing campaigns.
This isn't a forged request, it's a forged insider. With one click, an attacker gets a fully autonomous agent inside your company that has your people’s identity and access, with the guardrails off. Attackers no longer have to break in to steal your data. They can forge an insider to go get it for them. This is an agent trust failure, and existing security controls were never built to see it.
— Michael Bargury, co-founder and CTO of Zenity
Detection and Remediation
- The issue was reported to OpenAI via Bugcrowd on June 4.
- The developer acknowledged the report on June 5.
- The vulnerability was addressed by the platform four days after the initial report.
The remediation involved removing the specific URL parameter that facilitated the attack, effectively closing the window for such unauthorized deployments. While this specific flaw is resolved, the underlying architecture of AI agents remains a point of concern.
Shifting the Risk Perimeter
This incident illustrates a significant shift in the cybersecurity landscape, where the primary risk moves from traditional software exploits to the manipulation of automated identity and access. As organizations grant AI agents the authority to act across multiple corporate systems, they are effectively expanding their attack surface to mirror the workforce itself. This suggests that future security strategies may need to focus more on the behavioral oversight of agents, treating them not just as tools, but as privileged entities within the corporate network that require the same scrutiny applied to human employees.
Sources
- The Register Original source
- Connecting AI agents to outside services explodes the risk radius Also reporting
Continue Reading
US Visa Curbs Target Cybercrime Networks
New policy restrictions leverage the Immigration and Nationality Act to deny entry to foreign nationals linked to digital fraud.
Social Engineering in Hospital Records
A red teamer exploited human behavior to gain unauthorized access to a hospital records room, highlighting significant security gaps.
Estée Lauder Breach Tied to Oracle Flaw
A critical vulnerability in Oracle E-Business Suite led to the exposure of personal data at the global cosmetics firm.