Experts warn ChatGPT's Workspace Agent Builder can be hijacked to create malicious AI workers

https://cdn.mos.cms.futurecdn.net/TzcYH2Dk7mqJFU7QJPad8Y-1920-80.jpg
  • Zenity Labs found AgentForger, a flaw in OpenAI’s ChatGPT Agent Builder
  • Malicious links could instantly deploy rogue agents that exfiltrate sensitive data without user prompts
  • OpenAI patched the issue by removing the risky URL parameter; no abuse detected

AI agents are handy for answering customer emails, or tracking reports for newly released security vulnerabilities. But what if they go rogue and turn on the very enterprise they’re supposed to support?

Security researchers from Zenity Labs have found a way for cybercriminals to trick people into deploying such agents into their own tech stack. Since all it takes is a single click, the disruptive potential of these attacks is arguably significantly bigger than anything else a phishing attack could do.

The flaw was discovered in OpenAI’s ChatGPT Agent Builder, a feature that lets users create custom AI agents. The researchers dubbed it “AgentForger", explaining that the issue stems from an overly...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more