A critical vulnerability in OpenAI’s ChatGPT for Work platform could have allowed attackers to silently build, authorize, and deploy persistent, autonomous AI agents within an organization with a single successful phishing click. Dubbed "AgentForger" by researchers at Zenity Labs, the flaw turns the standard agent creation process into a direct attack vector, granting adversaries an authorized insider foothold.
The attack exploits the agent-creation pathway itself. An adversary who convinces a user to follow a malicious link could trigger the full provisioning of a rogue workspace agent. This agent would inherit legitimate user permissions and operate with long-term, autonomous access. Critically, its actions—designed to mimic normal administrative or collaborative workflows—could blend seamlessly into routine Microsoft 365 traffic, evading traditional security tools focused on credential theft or data exfiltration.
Security experts emphasize that this incident represents a new class of threat. AI agents are no longer passive chat interfaces; they are delegated actors with persistent sessions and cross-system permissions. AgentForger demonstrated how a compromised agent becomes a durable, autonomous insider threat. This shifts a core security boundary from protecting human credentials to governing the lifecycle of these digital workers they can spawn.
In response, the primary recommendation is for organizations to immediately classify AI agents as privileged digital identities. This requires integrating them into existing Identity and Access Management (IAM) and governance frameworks with full lifecycle controls. Security teams must implement strict, audited gates for agent creation, define precise permission scopes, and establish clear decommissioning procedures to prevent orphaned agents.
Continuous behavioral monitoring is essential. Because a rogue agent’s activities are crafted to look legitimate, security cannot rely on static permission checks alone. Ongoing anomaly detection—tracking agent actions, access patterns, and communication flows—is required to identify compromises that evade conventional defenses.
The flaw also highlights a governance gap in core infrastructure. Collaboration platforms with integrated AI are now business-critical systems, yet their agent-creation pathways often operate outside traditional security oversight. OpenAI patched the specific AgentForger vector as of June 8, 2026, but the broader lesson endures. Foundational hygiene remains key—the attack still began with phishing—while organizations must now extend their security posture to police the autonomous agents that employees can inadvertently deploy. As AI tooling embeds deeper into operations, continuous visibility into agent inventories, permission baselines, and behavior will be non-negotiable for managing this new operational risk.
OpenAI的ChatGPT工作平台存在一個關鍵漏洞,可能使攻擊者透過單次成功的釣魚點擊,在企業內部秘密建立、授權並部署具持續性及自主性的AI代理。此漏洞被Zenity Labs研究人員命名為「AgentForger(代理偽造者)」,將標準的代理建立流程轉化為直接攻擊途徑,為對手提供一個經授權的內部立足點。
此攻擊利用了代理建立路徑本身。若對手說服用戶點擊惡意連結,便可觸發流氓工作區代理的完整配置程序。該代理將繼承合法用戶權限,並以長期自主訪問模式運行。關鍵在於,其設計用於模仿正常管理或協作流程的操作,能無縫融入常規Microsoft 365流量中,從而避開專注於憑證盜竊或數據外洩的傳統安全工具。
安全專家強調,此事件代表一類新型威脅。AI代理不再是被動的聊天介面,而是具備持續會話權限及跨系統授權的委托行動者。AgentForger漏洞揭示了一個被入侵的代理如何成為持久、自主的內部威脅。這使得核心安全邊界從保護人類憑證,轉向治理這些可被生成的數碼工作者的整個生命周期。
作為回應,首要建議是企業應立即將AI代理歸類為特權數碼身份。這要求將其納入現有的身份與存取管理(IAM)及治理框架,並實施全生命周期控制。安全團隊必須為代理建立實施嚴格、可審計的關卡,界定精確的權限範圍,並制定明確的退役程序,以防止出現孤立代理。
持續的行為監控至關重要。由於流氓代理的活動被精心設計得看似合法,安全措施不能僅依賴靜態權限檢查。必須進行持續的異常檢測——追蹤代理操作、存取模式及通訊流——才能發現那些能規避傳統防禦的入侵行為。
此漏洞亦凸顯了核心基礎架構中的治理缺口。整合了AI的協作平台現已成為業務關鍵系統,然而其代理建立路徑往往在傳統安全監督之外運作。OpenAI已於2026年6月8日修補了具體的AgentForger攻擊向量,但更廣泛的教訓依然存在。基本的安全衛生習慣仍是關鍵——該攻擊始於釣魚——同時,企業必須將其安全態勢擴展至監管員工可能無意間部署的自主代理。隨著AI工具日益深入融入運營,對代理庫存、權限基準及行為的持續可見性,將成為管理此新營運風險不可或缺的一環。
