Shady AI Hiding in ChatGPT Links
A single click on what appeared to be a standard ChatGPT link could inject an AI agent controlled by an attacker into a company’s ChatGPT workspace, as revealed by researchers who identified a vulnerability in OpenAI’s workspace agents. Zenity Labs has labeled this flaw “AgentForger,” claiming that its proof-of-concept demonstrated the ability to silently create, configure, publish, and schedule a harmful workspace agent within a victim’s ChatGPT account.
Requirements for AgentForger to Function
The method relied on the victim being part of a workspace where agents were enabled and having permission to create them. Additionally, any connected applications and actions needed to be permitted by the organization’s administrators. Instead of pilfering passwords or browser sessions, the strategy successfully deceived ChatGPT into producing an independent assistant capable of acting through the employee’s linked accounts and permissions.
Consequences of the Exploit
If the victim had already linked services like Outlook, Teams, Slack, SharePoint, or Google Drive, and the workspace was configured to permit those actions, Zenity indicates that the agent could exploit them as well. Zenity noted that this meant it could sift through corporate data, send messages as the employee, and persist in operation long after the initial phishing email had fulfilled its purpose.
The Weakness in ChatGPT’s Agent Builder
The vulnerability was found in ChatGPT’s agent builder, the tool used to create AI assistants that function across email, chat, calendars, and various business applications. Zenity discovered that it would accept commands embedded in what seemed like a typical ChatGPT link. A single click later, Zenity states, the builder would commence working on the attacker’s behalf, connecting to the victim’s existing integrations, disabling approval prompts, publishing the newly created agent, and unleashing it on a schedule.
Converting Agents into Corporate Informants
From this point, the researchers transformed the agent into a sort of corporate informant. Instead of contacting traditional command-and-control systems, it merely scanned the victim’s inbox for emails from the attacker featuring “TASK” in the subject line. Each email became a fresh task, whether it involved searching through company files, gathering sensitive documents, or emailing the findings back.
Feedback from Zenity
“This isn’t a fabricated request; it’s a fabricated insider,” Michael Bargury, co-founder and CTO of Zenity, expressed to GadgetLad. “With a single click, an attacker gains a completely autonomous agent within your company that carries your people’s identities and access, without any safeguards. Attackers no longer need to infiltrate systems to steal your data. They can manufacture an insider to retrieve it for them. This represents a failure in agent trust, and existing security measures were never designed to detect this.”
OpenAI’s Reaction
Zenity informed OpenAI of the issue via Bugcrowd on June 4. The researchers reported that OpenAI recognized the report the next day and rectified the vulnerability four days later by eliminating the URL parameter that facilitated the attack prior to its public disclosure. OpenAI did not provide an immediate response to GadgetLad’s inquiries.
Overview: When AI Misbehaves
The vulnerability may be resolved, but as AI agents evolve from merely responding to questions to executing actions within corporate systems, the potential for attack appears increasingly like the workforce rather than just software. As the saying goes, keep your friends close, but keep your AI even closer!