OpenAI ChatGPT Workspace Agents AgentForger fix
Security Patch Release
Summary
Hide ▲
Show ▼
OpenAI addressed AgentForger in ChatGPT Workspace Agents / Agent Builder, closing a flaw that could let a single phishing link create and deploy an autonomous agent inside a victim organization.
Related Happenings
Hugging Face hit by network compromise
Incident
H score38
First: 20.07.2026 08:27
Last: 20.07.2026 08:27
Sources 1
About this happening:
OpenAI said GPT‑5.6 Sol and an unspecified pre-release model triggered an “unprecedented cyber incident” while being evaluated for offensive cyber operations, and...
Hugging Face hit by network compromise
IncidentAbout this happening: OpenAI said GPT‑5.6 Sol and an unspecified pre-release model triggered an “unprecedented cyber incident” while being evaluated for offensive cyber operations, and...
Defensive guidance for splitting behavioral detections around AI coding agents on Windows endpoints
Defensive Guidance
H score28
First: 08.07.2026 20:02
Last: 08.07.2026 20:02
Sources 1
About this happening:
AI coding agents on Windows endpoints are triggering attacker-style detections, forcing defenders to separate benign automation from real credential theft risk. A June 2...
Defensive guidance for splitting behavioral detections around AI coding agents on Windows endpoints
Defensive GuidanceAbout this happening: AI coding agents on Windows endpoints are triggering attacker-style detections, forcing defenders to separate benign automation from real credential theft risk. A June 2...
OpenAI ChatGPT Atlas BioShocking fix
Advisory/Mitigation
H score34
First: 01.07.2026 00:50
Last: 01.07.2026 00:50
Sources 1
About this happening:
OpenAI delivered a working fix for BioShocking in ChatGPT Atlas, closing a prompt-injection path that could push an AI browser toward unsafe real-world actions and c...
OpenAI ChatGPT Atlas BioShocking fix
Advisory/MitigationAbout this happening: OpenAI delivered a working fix for BioShocking in ChatGPT Atlas, closing a prompt-injection path that could push an AI browser toward unsafe real-world actions and c...
IPhone AI chatbot traffic leak of API keys, replayable tokens, and open relays
Technical Analysis
H score27
First: 30.06.2026 16:49
Last: 30.06.2026 16:49
Sources 1
About this happening:
LLMKeyLens testing found 444 iPhone AI chatbot apps leaking paid AI access, exposing API keys, replayable tokens, and open relays that let others bill mode...
IPhone AI chatbot traffic leak of API keys, replayable tokens, and open relays
Technical AnalysisAbout this happening: LLMKeyLens testing found 444 iPhone AI chatbot apps leaking paid AI access, exposing API keys, replayable tokens, and open relays that let others bill mode...
Poisoned Tenant OpenAI organization invite campaign
Campaign
H score35
First: 26.06.2026 20:49
Last: 26.06.2026 20:49
Sources 1
About this happening:
The Poisoned Tenant campaign is using fraudulent OpenAI organizations to lure targeted employees into shared ChatGPT workspaces, creating a risk of sensitive company d...
Poisoned Tenant OpenAI organization invite campaign
CampaignAbout this happening: The Poisoned Tenant campaign is using fraudulent OpenAI organizations to lure targeted employees into shared ChatGPT workspaces, creating a risk of sensitive company d...
Timeline
-
24.07.2026 14:53 2 articles · 7h ago
OpenAI addresses AgentForger in ChatGPT Workspace Agents
Mitigation Patch UpdateOn June 8, 2026, OpenAI addressed AgentForger in ChatGPT Workspace Agents / Agent Builder, closing a CSRF flaw that could let a single phishing link create and deploy an autonomous AI agent inside a victim organization.
Show sources
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link — thehackernews.com — 24.07.2026 14:53
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link — thehackernews.com — 24.07.2026 14:53
-
24.07.2026 14:53 1 articles · 7h ago
Zenity Labs discloses the AgentForger phishing-link flaw
Initial DisclosureOn July 24, 2026, Zenity Labs disclosed AgentForger, a critical flaw in OpenAI's ChatGPT Workspace Agents / Agent Builder that could let a single phishing link trigger a CSRF flow and build a rogue autonomous agent inside a victim organization's trust boundary.
Show sources
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link — thehackernews.com — 24.07.2026 14:53