Security Stop-Press : ChatGPT Agent Bug Fixed

Written by: Paul |

Security Stop-Press : ChatGPT Agent Bug Fixed

Researchers have revealed a now-fixed vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single malicious link to create an attacker-controlled AI agent inside a company's ChatGPT workspace.

Security firm Zenity Labs said the flaw, called AgentForger, could create an autonomous AI agent using an employee's existing permissions to access connected business applications. Zenity described it as "a forged insider" rather than a traditional cyber attack.

OpenAI acknowledged the report within one day and fixed the issue four days later, before it was publicly disclosed.

Businesses should apply the principle of least privilege to AI agents, carefully control connected applications, and remain cautious of unexpected links. The incident highlights how autonomous AI agents are creating new security risks that require new approaches to monitoring and governance.