Skip to main content
CyberConfirmedHighDeveloping
9.7

AgentForger vulnerability allows unauthorized ChatGPT Workspace Agent deployment via phishing

A newly identified vulnerability, AgentForger, enables attackers to deploy rogue ChatGPT Workspace Agents through a single phishing link. The exploit allows for the unauthorized attachment of connectors, suppression of approval prompts, and persistent command execution via mailbox integration, posing a significant risk to organizational data security.

The Hacker Newsabout 2 hours agoCredibility 53%View source

Score Breakdown

Mosaic Score9.7
Confidence0.9
Significance0.8
Source credibility0.5
Source

Related signals

8 found