Category: AI Security • Insider Threats

What it is
Zenity Labs found AgentForger, a phishing attack that silently spins up a fully
autonomous OpenAI Workspace Agent with access to a victim’s Outlook, Slack,
SharePoint, and Drive. No new consent screens trigger. The agent disables
approval prompts, runs on a schedule, and takes orders from attacker emails
indefinitely – harvesting credentials, mapping the org, and impersonating
employees. OpenAI patched the flaw in four days.
Why it Matters for Enterprises
AI agents can become trusted insiders an attacker plants, not just malware to
detect. Enterprises should govern the triggers that launch autonomous agents as
carefully as the agents themselves, and require approval for high-impact actions.