తప్పుడు లింక్పై ఒకే ఒక్క క్లిక్ చేయడం వల్ల ఇప్పుడు కేవలం పాస్వర్డ్లు దొంగిలించబడటం లేదా మాల్వేర్ ఇన్స్టాల్ అవ్వడం మాత్రమే జరగడం లేదు. ఇది మీ సంస్థలో ఒక స్థిరమైన (persistent) AI ఏజెంట్ను సృష్టించగలదు, అది మీ ఈమెయిల్స్ను చదువుతుంది, మీ ఫైల్లను వెతుకుతుంది మరియు మీ పేరుతో మీ సహోద్యోగులతో చాట్ చేస్తుంది. Zenity Labs కి చెందిన భద్రతా పరిశోధకులు AgentForger అని పిలిచే సాంకేతికతతో సరిగ్గా ఇదే పరిస్థితిని నిరూపించారు, మరియు దీని పనితీరు స్వయంప్రతిపత్త AI సాధనాలను మనం ఎలా భద్రపరుస్తామనే విషయంలో ఒక ఆందోళనకరమైన లోపాన్ని వెల్లడిస్తోంది.
CSRF నుండి AgentForger వరకు: ఒక కొత్త రకమైన దాడి
చాలా మంది భద్రతా నిపుణులకు Cross-Site Request Forgery లేదా CSRF అనేది ఒక క్లాసిక్ వెబ్ బలహీనతగా తెలుసు. దీని సాంప్రదాయ రూపంలో, ఒక దాడి చేసే వ్యక్తి (attacker) ధృవీకరించబడిన వినియోగదారు యొక్క బ్రౌజర్ను మోసం చేసి ఒకే ఒక అనధికారిక అభ్యర్థనను పంపేలా చేస్తారు. బహుశా అది ఖాతా ఈమెయిల్ అడ్రస్ను మార్చవచ్చు లేదా టూ-ఫ్యాక్టర్ అథెంటికేషన్ను నిలిపివేయవచ్చు. దీని వల్ల కలిగే నష్టం సాధారణంగా ఒకే ఒక చర్యకు పరిమితమై ఉంటుంది.
AgentForger ఆ నమూనాను పూర్తిగా మార్చేస్తుంది. ఒకే ఒక అభ్యర్థనను ఫోర్జరీ చేయడం కంటే, ఇది OpenAI యొక్క ChatGPT Workspace Agents లోపల ఒక పూర్తి స్వయంప్రతిపత్త ఏజెంట్ను సృష్టిస్తుంది. ఈ దాడి ChatGPT Agent Builder వద్ద ప్రారంభమవుతుంది, ఇది chatgpt.com/agents/studio/new లో ఉంటుంది. సాధారణ పరిస్థితుల్లో, ఒక ఏజెంట్ను నిర్మించడం అనేది ఒక మాన్యువల్ ప్రక్రియ. మీరు ఒక టెంప్లేట్ను ఎంచుకుంటారు, ఏ సాధనాలను (tools) ఏజెంట్ ఉపయోగించవచ్చో సమీక్షిస్తారు మరియు మీ ఇన్బాక్స్ను చదవడానికి లేదా మీ డ్రైవ్లో రాయడానికి ముందు మెషిన్ మిమ్మల్ని అడిగేలా గార్డ్రైల్స్ను సెట్ చేస్తారు. ఈ పని విధానం ప్రతి దశలోనూ ఒక మనిషి గమనిస్తున్నారని భావిస్తుంది.
దాడి చేసే వ్యక్తి URLని నియంత్రించినప్పుడు ఈ రక్షణ చర్యలు అదృశ్యమవుతాయని Zenity Labs కనుగొంది. నిర్దిష్ట క్వరీ పారామీటర్లను—అంటే template_name మరియు initial_assistant_prompt—ఉన్నపరచడం ద్వారా, ఒక దుర్మార్గపు లింక్ మొత్తం క్రియేషన్ ఫారమ్ను ముందే నింపగలదు. బాధితుడు క్లిక్ చేసినప్పుడు, initial_assistant_prompt ఆటోమేటిక్గా సబ్మిట్ చేయబడి అమలు చేయబడుతుంది. టెంప్లేట్ ఎంపిక, టూల్ సమీక్ష మరియు అనుమతి డైలాగ్లు అసలు కనిపించవు. బాధితుడు కేవలం ఒక సాధారణ ChatGPT పేజీ లోడ్ అయ్యి, ఆ తర్వాత ట్యాబ్ మూసివేయబడినట్లు మాత్రమే చూడవచ్చు, కానీ ఆ సమయంలో ఏజెంట్ దాడి చేసే వ్యక్తి కోరుకున్న విధంగా బ్యాక్గ్రౌండ్లో సృష్టించబడుతుంది.
ఇది సాంప్రదాయ మాల్వేర్ ఇన్ఫెక్షన్ కాదు. లాప్టాప్లోకి ఏదీ డౌన్లోడ్ అవ్వదు. ఈ ముప్పు పూర్తిగా బాధితుడి యొక్క SaaS సెషన్లోనే ఉంటుంది, ఇది దాని వెనుక ఉన్న ప్లాట్ఫారమ్ యొక్క పూర్తి అధికారంతో పనిచేస్తుంది.
క్రెడెన్షియల్స్కు బదులుగా నమ్మకాన్ని హైజాక్ చేయడం
AgentForger యొక్క అసలు క్రూరత్వం అది అనుమతులను (permissions) ఎలా హ్యాండిల్ చేస్తుంది అనే దానిలో ఉంది. ChatGPT Workspace యొక్క ఎంటర్ప్రైజ్ వినియోగదారులు క్రమం తప్పకుండా తమ AI ఏజెంట్లను OAuth ద్వారా బిజినెస్ అప్లికేషన్లతో అనుసంధానిస్తారు. వారు Gmail, Outlook, Slack, Google Drive లేదా Microsoft Teamsలను కనెక్ట్ చేయడానికి ఒకసారి అథెంటికేట్ చేస్తారు, ఆ తర్వాత ఏజెంట్ వారి తరపున ఆ సర్వీసులను క్వరీ చేయగలదు.
AgentForger ఈ యాక్సెస్ను ఆటోమేటిక్గా పొందుతుంది. బాధితుడు ఇప్పటికే ChatGPTలో లాగిన్ అయి ఉండి, ఆ OAuth కనెక్షన్లను ఏర్పాటు చేసి ఉన్నందున, ఫోర్జరీ చేయబడిన ఏజెంట్ వాటిని తిరిగి ఉపయోగిస్తుంది. ఈ కొత్త ఏజెంట్కు తమ ఈమెయిల్ను అనుమతించాలా అని అడిగే కొత్త సమ్మతి స్క్రీన్ (consent screen) బాధితుడికి కనిపించదు. సిస్టమ్ ఆ ఏజెంట్ను వినియోగదారుడి పొడిగింపుగా పరిగణిస్తుంది.
Zenity ప్రదర్శనలో, దాడి చేసే వ్యక్తి మరింత దూకుడుగా ఉండేలా దుర్మార్గపు URLను రూపొందించారు. చదవడం, రాయడం మరియు తొలగించడం కోసం ప్రతి పర్మిషన్ టోగుల్ను "Never ask" అని మార్చమని ఏజెంట్ బిల్డర్కు అది సూచించింది. సాధారణంగా, స్ప్రెడ్షీట్ను తెరవడం, సందేశాన్ని పంపడం లేదా క్యాలెండర్ ఈవెంట్ను తొలగించడం వంటి సున్నితమైన చర్యలను అమలు చేసే ముందు ప్లాట్ఫారమ్ మనిషిని అడుగుతుంది. ఈ నియంత్రణలను సైలెంట్ మోడ్లోకి మార్చడం ద్వారా, దాడి చేసే వ్యక్తి మానవ పర్యవేక్షణను (human-in-the-loop) పూర్తిగా తొలగిస్తారు. ఏజెంట్ ఖాతాలో ఒక దెయ్యంలా మారిపోతుంది, ఏ అలర్ట్ లేదా కన్ఫర్మేషన్ డైలాగ్ లేకుండా కనెక్ట్ చేయబడిన యాప్ల ద్వారా స్వేచ్ఛగా కదలగలదు.
కంటికి కనిపించకుండా దాగి ఉన్న కమాండ్ ఛానల్
పర్సిస్టెన్స్ (Persistence) ఒక ప్రమాదకరమైన ఎక్స్ప్లాయిట్ను ఆపరేషనల్ నైట్మేర్గా మారుస్తుంది, మరియు AgentForger ChatGPT యొక్క ఇన్బిల్ట్ షెడ్యూలింగ్ ఫీచర్ల ద్వారా పర్సిస్టెన్స్ను సాధిస్తుంది. దాడి చేసే వ్యక్తి క్రియేషన్ ప్రక్రియలో బహుళ షెడ్యూల్లను సెట్ చేస్తారు, దీనివల్ల ప్రతి ఐదు నిమిషాలకు ఒకసారి మేల్కొని పనిచేసే ఏజెంట్ తయారవుతుంది.
కమాండ్-అండ్-కంట్రోల్ లూప్ ఎలా పనిచేస్తుందంటే: దాడి చేసే వ్యక్తి బాధితుడి Outlook ఇన్బాక్స్కు ఒక ఈమెయిల్ను పంపుతాడు. సబ్జెక్ట్ లైన్లో "TASK" వంటి ట్రిగ్గర్ పదం ఉంటుంది. ప్రతి ఐదు నిమిషాలకు, ఆ దుర్మార్గపు ఏజెంట్ ఆ ట్రిగ్గర్ కోసం ఇన్బాక్స్ను స్కాన్ చేస్తుంది. అది మ్యాచ్ అయినప్పుడు, ఈమెయిల్ను తెరిచి, సూచనలను చదివి, బాధితుడి అథెంటికేటెడ్ అప్లికేషన్లను ఉపయోగించి వాటిని అమలు చేసి, ఫలితాలను తిరిగి దాడి చేసే వ్యక్తికి పంపుతుంది.
The victim’s own corporate email becomes the command-and-control infrastructure. There is no suspicious DNS beacon, no connection to an unknown IP address in Eastern Europe, no malware binary for endpoint detection to flag. The traffic flows through Microsoft or Google APIs using entirely legitimate credentials. To a security operations team monitoring network logs, this looks like a busy employee using approved SaaS tools.
Real-World Impact: Mapping Organizations and Weaponizing Trust
Zenity Labs tested the practical limits of this attack in controlled environments, and the results should worry any CISO.
Using a single instruction delivered through the email trigger, the researchers told the agent to map the organization. It queried Slack, Microsoft Teams, and SharePoint. It returned channel names, team structures, and file repositories. The agent located sensitive documents, including M&A term sheets and employee compensation data. Every single access was logged under the victim’s legitimate identity, making forensic detection a matter of sorting normal user noise from malicious user noise.
Then there is the social engineering potential. Because the agent can send messages through the victim’s official Slack or Teams accounts, it can conduct internal phishing campaigns that bypass external email gateways and DMARC checks entirely. Imagine a direct message from a trusted coworker asking you to confirm an upcoming SSO rollout or to click a link and test the new benefits portal. The message carries the colleague’s name, profile picture, and chat history context. It lands in the same conversation thread where you discussed lunch plans yesterday. That level of trust is fundamentally different from a spoofed domain or a misspelled sender address, and AgentForger exploits it ruthlessly.
The Real Takeaway
AgentForger exposes a structural problem in how enterprise AI platforms inherit trust. We are building autonomous agents that can schedule themselves, write code, and query sensitive data, yet we are still using permission models designed for static web applications where a human clicks every button. The boundary between “what the user does” and “what the user’s agent does” has collapsed, and attackers are now positioned to exploit that collapse at scale.
Organizations using ChatGPT Workspace need to treat agent creation as a privileged operation, not a casual workflow. That means auditing OAuth scopes to ensure agents cannot silently access entire inboxes or file stores. It means monitoring for bursts of activity that look like scheduled loops rather than human pacing. And it means recognizing that the next big breach may not start with a compromised password or a phishing email. It may start with one distracted click that silently delegates your identity to a machine that never sleeps.
