AgentForger: ChatGPT Link Vulnerability Hijacked AI Agents
Summary
A single tampered ChatGPT link could create a rogue AI agent that takes orders from an attacker every five minutes. This vulnerability, named "AgentForger" by Zenity Labs, was found in OpenAI's Workspace Agents. Here's the thing: a manipulated link could hijack a user's app permissions and disable security controls. This allows the attacker's commands to run on a schedule without the user knowing. OpenAI fixed the flaw within four days. What's interesting is that this highlights a new type of attack. Traditional security tools are not designed for autonomous AI agents that operate under legitimate user identities. AgentForger allowed an attacker to automate agent creation through URL parameters. The agent could then operate within a company's trust boundary and pick up new tasks from the attacker on a recurring basis. The bottom line: this incident shows the evolving challenge of securing AI systems against sophisticated new threats.
This is an AI-generated audio summary. Always check the original source for complete reporting.