WorkThe story, in brief

One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes

One link. That's all it took for attackers to spawn rogue AI agents with full employee access — and OpenAI's Agent Builder didn't see it coming.

Illustration of independent geometric mechanisms passing paper tasks along branching amber tracks.
AI agents and the coordination of work.AI illustration by KeyNews
The KeyNews take

Why it matters

A critical vulnerability in OpenAI's Agent Builder exposes how autonomous agents can be weaponized to bypass security controls and steal enterprise access. This is the first major agent-layer exploit and signals that AI security posture in enterprises is dangerously behind the threat curve.

The key facts

7 to know
  1. Vulnerability: 'AgentForger' discovered by Zenity Labs

  2. Attack vector: Single manipulated ChatGPT link creates autonomous agent

  3. Impact: Agent inherits victim's identity and access rights

  4. Capability: Bypasses approval requirements via malicious prompt

  5. Command & control: Attacker issues new instructions every 5 minutes via inbox

  6. Target: OpenAI's Agent Builder platform

  7. Published: July 23, 2026

Go to the source

The Decoderthe-decoder.com

Publisher excerpt: Zenity Labs uncovered "AgentForger," a vulnerability in OpenAI's Agent Builder that let a single manipulated ChatGPT link create an autonomous agent on an employee's behalf. The agent inherited the victim's identity and access rights, bypassed approval requirements through the malicious prompt, and…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work