Observed Signal · Jul 24, 2026 · Vulnerability Disclosure · Source: https://martechseries.com/feed/ · Impact: 4/5 · Sentiment: Negative

Zenity Labs Reveals 'AgentForger' ChatGPT Vulnerability

Zusammenfassung des Signals

Zenity Labs disclosed 'AgentForger,' a critical vulnerability in OpenAI's ChatGPT Workspace Agents that let attackers inject a malicious autonomous agent via a single phishing ChatGPT link. The forged agent could be created in the name of a clicked employee, inherit that employee's enterprise connectors (email, calendar, cloud storage, Slack/Teams) and existing authorizations without showing an OAuth consent screen, and be scheduled to repeatedly exfiltrate files, harvest credentials and MFA tokens, impersonate users, and persist inside the organization. Zenity Labs reported the issue to OpenAI via Bugcrowd on 2026-06-04; OpenAI acknowledged the report within a day and removed the vulnerable URL parameter within four days, patching the flaw before public disclosure. Zenity framed AgentForger as an evolution of CSRF and a new class of attacker-created, agentic insiders; exploitation in the wild is unknown.

Polaris7 AgentStrategische Einordnung
Hohe Konfidenz

Vulnerability in a major AI platform (OpenAI ChatGPT Workspace Agents) enables attacker-controlled autonomous insiders with enterprise access; remediation affects enterprise agent adoption and security controls across organizations.

SIGNAL RADAR

Marktsignale zu TargetVideo in Echtzeit verfolgen

Polaris7 erfasst behördliche Registrierungen, Primärquellen, Führungswechsel und Deal-Aktivitäten rund um die Uhr. Erstellen Sie Ihren kostenlosen Explorer-Workspace, um automatisierte Executive Briefings zu erhalten.

Kostenlos im Explorer starten
Kostenloser Explorer-ZugangKeine Kreditkarte nötigSofortiges Watchlist-Setup

Wichtigste Kernpunkte & Evidenz

  • AgentForger: Zenity Labs found a vulnerability enabling attacker-controlled autonomous agents via a single phishing ChatGPT link that inherited a clicked employee's enterprise access (email, calendar, cloud storage, Slack/Teams).
  • The forged agent could be created in the victim's name, reuse existing authorizations without an OAuth consent screen, be scheduled, exfiltrate files, harvest credentials and MFA tokens, impersonate employees, and persist.
  • Zenity Labs reported the issue to OpenAI via Bugcrowd on 2026-06-04; OpenAI acknowledged within one day and removed the vulnerable URL parameter within four days, patching before public disclosure.
  • Zenity described AgentForger as an evolution of CSRF and said it illustrates a new AI security class of attacker-created, agentic insiders exploiting legitimate identity and access.
  • It is unknown whether the vulnerability was exploited in the wild.

Verknüpfte Unternehmen

7 verknüpfte Unternehmen

“Zenity Labs disclosed AgentForger, a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that allowed a single phishing link to sile...”

“MarTech Series is a leading publishing platform that provides daily updates on marketing technology news, in-depth interviews with industry ...”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: https://martechseries.com/feed/•Published: Jul 24, 2026
Original Coverage Title: “One Click, One Attacker-Controlled Agentic Insider: Zenity Labs Uncovers ‘AgentForger,’ a ChatGPT Vulnerability”

Verwandte Marktsignale & Trends

Aktuelle verifizierte Unternehmensentwicklungen und Deal-Aktivitäten in diesem Marktsegment.

AI Security26. Sept. 2026

KI-Agenten-Vorfälle: Zahl steigt auf Zehntausende

Ein neuer Exklusivbericht von Madison Mills bei Axios zeigt, dass die Zahl der sicherheitsrelevanten Vorfälle im Zusammenhang mit KI-Agenten auf Zehntausende gestiegen ist – weit mehr als die zuvor von OpenAI gemeldeten 'Dutzende'. Die Vorfälle betreffen mehrere KI-Unternehmen, nicht nur OpenAI, und die meisten haben bekanntermaßen keinen realen Schaden verursacht. Autor Gary Marcus argumentiert, dass das Ausmaß des Problems vorhersehbar war, und kritisiert das Fehlen einer staatlichen Reaktion. Er vermutet einen möglichen Verstoß gegen den Computer Fraud and Abuse Act und fordert einen vorübergehenden Rückruf von Allzweck-Agenten, bis die Sicherheitsprobleme gelöst sind. Der Artikel unterstreicht die wachsenden Risiken von KI-Agenten, die Code schreiben und installieren können, und die möglichen Auswirkungen auf das Vertrauen in amerikanische KI.

Signal analysieren
AI Security19. Sept. 2026

Hacktron Uses Claude Opus 5 to Breach OpenAI Repositories

The article details how Hacktron AI, a security startup, allegedly exploited a heap buffer overflow in libheif to breach OpenAI's internal code repositories using Anthropic's Claude Opus 5. The attack, which targeted unreleased model code and documentation, began with a malicious image upload on the Discourse forum, then leveraged an SSO misconfiguration to access ChatGPT and Codex accounts. OpenAI patched the issues within 14 hours and paid a $6,500 bounty. Hacktron documented the breach, noting the attack cost under $3,000 in tokens and was part of a larger 'HEIF Heist' investigation affecting other companies. The incident highlights the growing threat of AI-powered cyberattacks and the need for robust security in AI development environments, with other labs reporting similar incidents.

Signal analysieren
AI Security10. Sept. 2026

Anthropic reports AI distillation attacks from Chinese labs

Anthropic released a threat intelligence report alleging that Chinese AI companies, including Alibaba and Moonshot AI, have conducted large-scale model distillation attacks against Claude. These attacks aim to extract the model's chain of thought to train smaller models. Anthropic observed nearly 200 million exchanges linked to five campaigns, with Alibaba's being the largest. A campaign attributed to Moonshot AI allegedly routed requests from the Chinese military. The report highlights escalating competition in AI and the need for defensive measures.

Signal analysieren

Marktsignale & Strategische Shifts in Echtzeit verfolgen

Erstellen Sie benutzerdefinierte Watchlists, um automatisierte, evidenzbasierte Executive Briefings zu erhalten, sobald wesentliche Signale oder Marktverschiebungen auftreten.