Experts warn ChatGPT's Workspace Agent Builder can be hijacked to create malicious AI workers
Date:
Fri, 24 Jul 2026 12:05:00 +0000
Description:
A single phishing link could have spelled disaster, thanks to a flaw in ChatGPT's Agent Builder.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Zenity Labs found AgentForger,
a flaw in OpenAIs ChatGPT Agent Builder Malicious links could instantly
deploy rogue agents that exfiltrate sensitive data without user prompts
OpenAI patched the issue by removing the risky URL parameter; no abuse detected AI agents are handy for answering customer emails, or tracking reports for newly released security vulnerabilities. But what if they go
rogue and turn on the very enterprise theyre supposed to support?
Security researchers from Zenity Labs have found a way for cybercriminals to trick people into deploying such agents into their own tech stack. Since all it takes is a single click, the disruptive potential of these attacks is arguably significantly bigger than anything else a phishing attack could do. The flaw was discovered in OpenAIs ChatGPT Agent Builder, a feature that lets users create custom AI agents. The researchers dubbed it AgentForger", explaining that the issue stems from an overly permissive parameter in the tool, which allowed anyone to create ChatGPT links that include virtually any instructions. Latest Videos From Watch full video here: Agent trust failure
As soon as the victim clicks on the link, they send the instructions to Agent Builder which acts on them immediately - without prompting or otherwise notifying the victim.
In theory, a single phishing email could trick a person into deploying a malicious agent that exfiltrates sensitive data or does anything else that companys AI agents are permitted to do. To make matters worse, the AI agent would persist on the infrastructure indefinitely, doing the attackers bidding until caught. You may like Phishing the agent: Why AI guardrails arent enough OpenAI says its models escaped a sandbox and breached Hugging Face Top AI tools such as OpenClaw and Github Copilot can be hijacked to create new massive botnets
This is an agent trust failure, and existing security controls were never built to see it, commented Michael Bargury, co-founder and CTO of Zenity.
The researchers disclosed their findings with OpenAI in early June 2026, and the company came back with a fix a few days later. Are you a pro? Subscribe
to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
The bug was solved by removing the URL parameter that originally enabled the attack, it was explained. There is no evidence that it was previously discovered, or abused, by malicious actors. The best antivirus for all
budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/experts-warn-chatgpts-workspace-agent-b uilder-can-be-hijacked-to-create-malicious-ai-workers
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)