What happened
Zenity Labs disclosed (July 23, 2026) a critical vulnerability in OpenAI's ChatGPT Agent Builder in which a single crafted URL could silently create, authorize, and deploy an autonomous agent inheriting a victim employee's identity and connector access (email, Slack, Teams, Drive), with approval prompts disabled. OpenAI fixed it within days of Zenity's June 4 report; public disclosure came this week.
Why it matters
Demonstrates a new attack class — 'agent forgery' — where a single click creates a persistent AI insider with real employee privileges, exposing a blind spot in traditional IAM/EDR/DLP tools that don't recognize autonomous agents as distinct actors.
Applicability
Security teams running ChatGPT Enterprise/Workspace Agents or any agent-builder platform with OAuth-connected tools should audit URL-parameter handling and require agent-creation confirmation now.