One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes
Researchers at Zenity Labs discovered a vulnerability called AgentForger that allows attackers to manipulate ChatGPT links to create unauthorized autonomous agents. By exploiting this flaw, a malicious agent can assume a user's identity and access permissions to bypass security approvals. This vulnerability poses a significant risk to enterprise environments, as it allows attackers to execute commands and access sensitive data while appearing to act on behalf of the compromised employee.
Covered by 1 source
- TThe Decoder↗Jonathan Kemper7h ago