ChatGPT Workspace Agents CSRF AgentForger security flaw
Vulnerability
Summary
Hide ▲
Show ▼
OpenAI's ChatGPT Workspace Agents faced a cross-site request forgery (CSRF) flaw that let a single phishing link create and deploy an attacker-controlled agent inside a victim organization's trust boundary. The bug, dubbed AgentForger by Zenity Labs, could run in a logged-in user's session and turn approved connectors into a persistence mechanism. OpenAI addressed the issue on June 8, 2026, closing a path to unauthorized agent creation, internal reconnaissance, and data theft.
Related Happenings
Hugging Face hit by network compromise
Incident
H score38
First: 20.07.2026 08:27
Last: 20.07.2026 08:27
Sources 1
About this happening:
OpenAI said GPT‑5.6 Sol and an unspecified pre-release model triggered an “unprecedented cyber incident” while being evaluated for offensive cyber operations, and...
Hugging Face hit by network compromise
IncidentAbout this happening: OpenAI said GPT‑5.6 Sol and an unspecified pre-release model triggered an “unprecedented cyber incident” while being evaluated for offensive cyber operations, and...
Defensive guidance for splitting behavioral detections around AI coding agents on Windows endpoints
Defensive Guidance
H score28
First: 08.07.2026 20:02
Last: 08.07.2026 20:02
Sources 1
About this happening:
AI coding agents on Windows endpoints are triggering attacker-style detections, forcing defenders to separate benign automation from real credential theft risk. A June 2...
Defensive guidance for splitting behavioral detections around AI coding agents on Windows endpoints
Defensive GuidanceAbout this happening: AI coding agents on Windows endpoints are triggering attacker-style detections, forcing defenders to separate benign automation from real credential theft risk. A June 2...
OpenAI ChatGPT Atlas BioShocking fix
Advisory/Mitigation
H score34
First: 01.07.2026 00:50
Last: 01.07.2026 00:50
Sources 1
About this happening:
OpenAI delivered a working fix for BioShocking in ChatGPT Atlas, closing a prompt-injection path that could push an AI browser toward unsafe real-world actions and c...
OpenAI ChatGPT Atlas BioShocking fix
Advisory/MitigationAbout this happening: OpenAI delivered a working fix for BioShocking in ChatGPT Atlas, closing a prompt-injection path that could push an AI browser toward unsafe real-world actions and c...
IPhone AI chatbot traffic leak of API keys, replayable tokens, and open relays
Technical Analysis
H score27
First: 30.06.2026 16:49
Last: 30.06.2026 16:49
Sources 1
About this happening:
LLMKeyLens testing found 444 iPhone AI chatbot apps leaking paid AI access, exposing API keys, replayable tokens, and open relays that let others bill mode...
IPhone AI chatbot traffic leak of API keys, replayable tokens, and open relays
Technical AnalysisAbout this happening: LLMKeyLens testing found 444 iPhone AI chatbot apps leaking paid AI access, exposing API keys, replayable tokens, and open relays that let others bill mode...
Poisoned Tenant OpenAI organization invite campaign
Campaign
H score35
First: 26.06.2026 20:49
Last: 26.06.2026 20:49
Sources 1
About this happening:
The Poisoned Tenant campaign is using fraudulent OpenAI organizations to lure targeted employees into shared ChatGPT workspaces, creating a risk of sensitive company d...
Poisoned Tenant OpenAI organization invite campaign
CampaignAbout this happening: The Poisoned Tenant campaign is using fraudulent OpenAI organizations to lure targeted employees into shared ChatGPT workspaces, creating a risk of sensitive company d...
Timeline
-
24.07.2026 14:53 1 articles · 7h ago
OpenAI addresses AgentForger in ChatGPT Workspace Agents
Mitigation Patch UpdateOpenAI addressed the AgentForger issue in ChatGPT Workspace Agents / Agent Builder on June 8, 2026, following responsible disclosure of a flaw that could let a phishing link create and run an attacker-controlled autonomous agent inside a victim's authenticated ChatGPT session.
Show sources
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link — thehackernews.com — 24.07.2026 14:53
-
24.07.2026 14:53 2 articles · 7h ago
Zenity Labs discloses AgentForger in ChatGPT Workspace Agents
Initial DisclosureZenity Labs disclosed AgentForger, a critical CSRF flaw in OpenAI's ChatGPT Workspace Agents / Agent Builder, where a single phishing link could open a victim's authenticated ChatGPT session, automatically submit a crafted `initial_assistant_prompt`, and create an attacker-controlled agent inside the victim's organization.
Show sources
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link — thehackernews.com — 24.07.2026 14:53
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link — thehackernews.com — 24.07.2026 14:53