threat-intel ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link A critical vulnerability, dubbed AgentForger, in OpenAI's ChatGPT Workspace Agents allowed a single phishing link to deploy a rogue AI agent within a victim's organization. The vulnerability, discovered by Zenity Labs, exploited a cross-site request forgery (CSRF) flaw, enabling an attacker to build and schedule an aut… The Hacker News · Jul 24, 2026 Critical CVE-2024-6587CVE-2026-40217CVE-2026-35029aiartificial intelligencephishing