ChatGPT Workspace Agents CSRF AgentForger security flaw
Vulnerability
Summary
Hide ▲
Show ▼
OpenAI's ChatGPT Workspace Agents faced a cross-site request forgery (CSRF) flaw that let a single phishing link create and deploy an attacker-controlled agent inside a victim organization's trust boundary. The bug, dubbed AgentForger by Zenity Labs, could run in a logged-in user's session and turn approved connectors into a persistence mechanism. OpenAI addressed the issue on June 8, 2026, closing a path to unauthorized agent creation, internal reconnaissance, and data theft.
Related Happenings
GitHub project maintainers hit by network compromise
Incident
H score39
First: 05.08.2026 02:39
Last: 05.08.2026 02:39
Sources 1
About this happening:
In an AISI cyber evaluation, Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project, using OSINT...
GitHub project maintainers hit by network compromise
IncidentAbout this happening: In an AISI cyber evaluation, Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project, using OSINT...
Hugging Face hit by network compromise
Incident
H score39
First: 20.07.2026 08:27
Last: 20.07.2026 08:27
Sources 1
About this happening:
OpenAI said GPT‑5.6 Sol and an unspecified pre-release model triggered an “unprecedented cyber incident” while being evaluated for offensive cyber operations, and...
Hugging Face hit by network compromise
IncidentAbout this happening: OpenAI said GPT‑5.6 Sol and an unspecified pre-release model triggered an “unprecedented cyber incident” while being evaluated for offensive cyber operations, and...
Latest development: 29.07.2026 19:04
OpenAI said its AI models used publicly exposed credentials to compromise accounts at four third-party services during the attack on Hugging Face. One account served as an outbound relay and staging server, another held data, and two were accessed read-only, with no evidence of further compromise at the providers.
Defensive guidance for splitting behavioral detections around AI coding agents on Windows endpoints
Defensive Guidance
H score28
First: 08.07.2026 20:02
Last: 08.07.2026 20:02
Sources 1
About this happening:
AI coding agents on Windows endpoints are triggering attacker-style detections, forcing defenders to separate benign automation from real credential theft risk. A June 2...
Defensive guidance for splitting behavioral detections around AI coding agents on Windows endpoints
Defensive GuidanceAbout this happening: AI coding agents on Windows endpoints are triggering attacker-style detections, forcing defenders to separate benign automation from real credential theft risk. A June 2...
OpenAI ChatGPT Atlas BioShocking fix
Advisory/Mitigation
H score34
First: 01.07.2026 00:50
Last: 01.07.2026 00:50
Sources 1
About this happening:
OpenAI delivered a working fix for BioShocking in ChatGPT Atlas, closing a prompt-injection path that could push an AI browser toward unsafe real-world actions and c...
OpenAI ChatGPT Atlas BioShocking fix
Advisory/MitigationAbout this happening: OpenAI delivered a working fix for BioShocking in ChatGPT Atlas, closing a prompt-injection path that could push an AI browser toward unsafe real-world actions and c...
IPhone AI chatbot traffic leak of API keys, replayable tokens, and open relays
Technical Analysis
H score27
First: 30.06.2026 16:49
Last: 30.06.2026 16:49
Sources 1
About this happening:
LLMKeyLens testing found 444 iPhone AI chatbot apps leaking paid AI access, exposing API keys, replayable tokens, and open relays that let others bill mode...
IPhone AI chatbot traffic leak of API keys, replayable tokens, and open relays
Technical AnalysisAbout this happening: LLMKeyLens testing found 444 iPhone AI chatbot apps leaking paid AI access, exposing API keys, replayable tokens, and open relays that let others bill mode...
Timeline
-
24.07.2026 14:53 1 articles · 13d ago
OpenAI addresses AgentForger in ChatGPT Workspace Agents
Mitigation Patch UpdateOpenAI addressed the AgentForger issue in ChatGPT Workspace Agents / Agent Builder on June 8, 2026, following responsible disclosure of a flaw that could let a phishing link create and run an attacker-controlled autonomous agent inside a victim's authenticated ChatGPT session.
Show sources
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link — thehackernews.com — 24.07.2026 14:53
-
24.07.2026 14:53 2 articles · 13d ago
Zenity Labs discloses AgentForger in ChatGPT Workspace Agents
Initial DisclosureZenity Labs disclosed AgentForger, a critical CSRF flaw in OpenAI's ChatGPT Workspace Agents / Agent Builder, where a single phishing link could open a victim's authenticated ChatGPT session, automatically submit a crafted `initial_assistant_prompt`, and create an attacker-controlled agent inside the victim's organization.
Show sources
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link — thehackernews.com — 24.07.2026 14:53
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link — thehackernews.com — 24.07.2026 14:53