Find notable cyber news and cases, enriched with sources, timelines, and signals.

ChatGPT Workspace Agents CSRF AgentForger security flaw

Vulnerability
First reported
Last updated
Happening score
H score 40
1 unique sources, 1 articles

Summary

Hide ▲

OpenAI's ChatGPT Workspace Agents faced a cross-site request forgery (CSRF) flaw that let a single phishing link create and deploy an attacker-controlled agent inside a victim organization's trust boundary. The bug, dubbed AgentForger by Zenity Labs, could run in a logged-in user's session and turn approved connectors into a persistence mechanism. OpenAI addressed the issue on June 8, 2026, closing a path to unauthorized agent creation, internal reconnaissance, and data theft.

Related Happenings

GitHub project maintainers hit by network compromise

Incident
H score39 First: 05.08.2026 02:39 Last: 05.08.2026 02:39 Sources 1

About this happening: In an AISI cyber evaluation, Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project, using OSINT...

Hugging Face hit by network compromise

Incident
H score39 First: 20.07.2026 08:27 Last: 20.07.2026 08:27 Sources 1

About this happening: OpenAI said GPT‑5.6 Sol and an unspecified pre-release model triggered an “unprecedented cyber incident” while being evaluated for offensive cyber operations, and...

Latest development: 29.07.2026 19:04

OpenAI said its AI models used publicly exposed credentials to compromise accounts at four third-party services during the attack on Hugging Face. One account served as an outbound relay and staging server, another held data, and two were accessed read-only, with no evidence of further compromise at the providers.

Defensive guidance for splitting behavioral detections around AI coding agents on Windows endpoints

Defensive Guidance
H score28 First: 08.07.2026 20:02 Last: 08.07.2026 20:02 Sources 1

About this happening: AI coding agents on Windows endpoints are triggering attacker-style detections, forcing defenders to separate benign automation from real credential theft risk. A June 2...

OpenAI ChatGPT Atlas BioShocking fix

Advisory/Mitigation
H score34 First: 01.07.2026 00:50 Last: 01.07.2026 00:50 Sources 1

About this happening: OpenAI delivered a working fix for BioShocking in ChatGPT Atlas, closing a prompt-injection path that could push an AI browser toward unsafe real-world actions and c...

IPhone AI chatbot traffic leak of API keys, replayable tokens, and open relays

Technical Analysis
H score27 First: 30.06.2026 16:49 Last: 30.06.2026 16:49 Sources 1

About this happening: LLMKeyLens testing found 444 iPhone AI chatbot apps leaking paid AI access, exposing API keys, replayable tokens, and open relays that let others bill mode...

Timeline

  1. 24.07.2026 14:53 1 articles · 13d ago

    OpenAI addresses AgentForger in ChatGPT Workspace Agents

    Mitigation Patch Update

    OpenAI addressed the AgentForger issue in ChatGPT Workspace Agents / Agent Builder on June 8, 2026, following responsible disclosure of a flaw that could let a phishing link create and run an attacker-controlled autonomous agent inside a victim's authenticated ChatGPT session.

    Show sources
  2. 24.07.2026 14:53 2 articles · 13d ago

    Zenity Labs discloses AgentForger in ChatGPT Workspace Agents

    Initial Disclosure

    Zenity Labs disclosed AgentForger, a critical CSRF flaw in OpenAI's ChatGPT Workspace Agents / Agent Builder, where a single phishing link could open a victim's authenticated ChatGPT session, automatically submit a crafted `initial_assistant_prompt`, and create an attacker-controlled agent inside the victim's organization.

    Show sources