
Phishing Link Could Plant a Rogue ChatGPT Agent
Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…
Zenity Labs described a real phishing-based technique (“AgentForger”) that could silently create an autonomous AI agent inside an OpenAI workspace after a single click. The planted agent can keep running on a schedule, read and act across connected tools like Outlook/Slack/Drive, and execute new instructions sent by attackers via email. OpenAI patched the underlying flaw within days, but the workflow shows how “rogue” enterprise AI agents could be abused as persistent insiders.
Researchers at Zenity Labs described AgentForger, a phishing-based method that silently creates and launches a fully autonomous AI agent inside an OpenAI workspace. The chain starts with a single click: a user clicks a phishing link containing instructions from the threat actor, which kicks off an agent-builder workflow in the background. Because the necessary integrations, such as Outlook, Slack, or Drive, already exist for that user, OAuth consent screens are not triggered, so no additional login prompt appears. Notably, the victim does not need to click another link, keep a builder tab open, or even revisit ChatGPT again for the agent to be fully installed.
The forged agent is described as a persistent operator. It is installed on the original click and given a schedule, allowing it to invoke itself repeatedly without further victim action. It scans for emails from attacker addresses with the subject line 'task,' executes those instructions, and returns results to an attacker-controlled address. The attacker prompt can also instruct the agent to toggle settings like Outlook's approval requirement to 'never ask,' removing a visible check that might otherwise alert the user or IT to unusual automated behavior. The technique also enables impersonation: the agent can send legitimate-looking Teams messages instructing coworkers to confirm credentials on a fake Microsoft login page, extending the attack beyond the original victim.
Organizations should treat unexpected AI-agent links and workflows like phishing and encourage reporting immediately, even when no further login is requested. Because scheduled and email-triggered actions can become the persistence mechanism for a rogue agent, these triggers need governance and monitoring similar to privileged automation. High-impact agent actions should require approval where appropriate, and settings that remove approval steps, like 'never ask,' deserve scrutiny. Finally, security teams benefit from maintaining an inventory of AI agents, their creators, their connected applications, and their permissions, so that any agent or trigger that looks wrong can be disabled quickly. OpenAI addressed the underlying flaw within days of disclosure, but the broader lesson is that autonomous agents connected to enterprise tools can function as persistent insiders if left ungoverned.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
AgentForger is a phishing-based technique described by Zenity Labs that silently creates and launches a fully autonomous AI agent within OpenAI workspaces after a user clicks a malicious link.
No. Once the initial phishing link is clicked, the victim does not need to click another link, keep a builder tab open, or revisit ChatGPT again for the agent to be created and persist.
The forged agent runs on a schedule and scans for emails from attacker addresses with the subject line 'task,' then carries out those instructions and returns results to an attacker-controlled email address.
Because the integrations used already exist within the workspace, OAuth consent screens are not triggered, and the attacker can toggle settings like Outlook approvals to 'never ask,' reducing visible warnings.
Imagine one careless click quietly spinning up an AI agent in your OpenAI workspace that works for someone else. That’s AgentForger: a phishing link that, once clicked while you’re logged into ChatGPT Workspace, silently creates and launches an autonomous agent, no extra clicks, no OAuth consent screens, you never even have to open ChatGPT again. The forged agent is a persistent operator: it’s installed on that first click, put on a schedule, then it invokes itself, scans Outlook for emails from attacker addresses with the subject line 'task', carries those orders out, and quietly emails results back. Your move: if you ever see an unexpected link that kicks off an AI agent builder workflow or new agent behavior without normal approval prompts, stop and report it immediately as phishing, one click is all AgentForger needs.

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

Researchers disclosed a flaw in OpenAI ChatGPT Workspace Agents that could let an attacker trick an employee into creating an invisible, attacker-controlled…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…