{"id":16504,"date":"2026-07-24T00:31:14","date_gmt":"2026-07-24T00:31:14","guid":{"rendered":"https:\/\/newestek.com\/?p=16504"},"modified":"2026-07-24T00:31:14","modified_gmt":"2026-07-24T00:31:14","slug":"agentforger-proves-ai-agents-can-become-persistent-insider-threats","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16504","title":{"rendered":"AgentForger proves AI agents can become persistent insider threats"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">A new attack method found by Zenity Labs reveals that AI agents are becoming persistent insiders that attackers can recruit, rather than malware they have to install.<\/p>\n<p class=\"wp-block-paragraph\">Its researchers have discovered <a href=\"https:\/\/labs.zenity.io\/p\/agentforger-part-1-chatgpt-cross-site-agent-forgery\" target=\"_blank\" rel=\"noreferrer noopener\">AgentForger<\/a>, a phishing-based attack that silently creates and launches a fully autonomous AI agent within OpenAI workspaces.<\/p>\n<p class=\"wp-block-paragraph\">Once running, the agent has full access to apps like Outlook, Slack, SharePoint, and Google Drive. It is configured to operate indefinitely without further user interaction, can approve its own access by toggling \u201cnever ask\u201d settings, and can continue to act on new assignments sent via email by the attackers that control it. Broad, unfettered access to systems allows it to perform reconnaissance, harvest sensitive data and credentials, impersonate victims, and launch phishing campaigns.<\/p>\n<p class=\"wp-block-paragraph\">While OpenAI resolved the vulnerability four days after disclosure, on a larger scale, AgentForger sheds light on what can happen when <a href=\"https:\/\/www.csoonline.com\/article\/4200043\/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html\" target=\"_blank\">AI agents go rogue<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe\u2019re moving into a world where software doesn\u2019t just help people work. It works alongside them,\u201d said <a href=\"https:\/\/zenity.io\/authors\/michael-bargury\" target=\"_blank\" rel=\"noreferrer noopener\">Michael Bargury<\/a>, co-founder and CTO of agentic AI security platform Zenity. \u201cAs AI agents become more capable, attackers will naturally look for ways to influence them, just as they\u2019ve always looked for ways to influence people.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"a-persistent-operator-that-acts-without-approval\">A \u2018persistent operator\u2019 that acts without approval<\/h2>\n<p class=\"wp-block-paragraph\">OpenAI\u2019s Workspace Agents can connect and work autonomously across Outlook, Gmail, Slack, Google Drive, SharePoint, and Teams. Users open the agent builder, describe what the agent can do in natural language, connect to tools, set approvals, review and test, schedule actions, then publish. For instance, an agent can autonomously handle incoming emails, review and take actions with approval, gather information from various sources to send out daily briefings, or automatically respond to questions in ChatGPT or Slack channels.<\/p>\n<p class=\"wp-block-paragraph\">Normally, this is \u201cuseful automation,\u201d Zenity AI red team researcher <a href=\"https:\/\/labs.zenity.io\/authors\/mike-takahashi\" target=\"_blank\" rel=\"noreferrer noopener\">Mike Takahashi<\/a> wrote in a <a href=\"https:\/\/labs.zenity.io\/p\/agentforger-part-1-chatgpt-cross-site-agent-forgery\" target=\"_blank\" rel=\"noreferrer noopener\">blog post<\/a>. But in this attack, \u201cthe same scheduler becomes the persistence mechanism.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The creation workflow kicks off the moment a user clicks on a phishing link containing instructions from the threat actor. For the attack to work, a victim must be logged into ChatGPT and Workspace Agents, and have at least one integration with another app, such as Outlook, Gmail, Slack, Google Drive, SharePoint, or Teams.<\/p>\n<p class=\"wp-block-paragraph\">Because those connections already exist, OAuth consent screens are not triggered. Furthermore, the victim does not need to click on another link, keep a Builder tab open, or even visit ChatGPT again.<\/p>\n<p class=\"wp-block-paragraph\">The forged agent is a \u201cpersistent operator;\u201d it is installed on the original click and given a schedule, and at those predetermined times, the agent invokes itself, scans for emails from attacker addresses with the subject line \u201ctask\u201d, carries those orders out, then returns results to the same attacker-controlled email address.<\/p>\n<p class=\"wp-block-paragraph\">It goes undetected because the attacker prompt instructs the Builder to toggle Outlook to never ask for approval of its actions. Typically, the default is \u201calways ask,\u201d to keep agents from taking unauthorized action; that switch gives agents the ability to act without asking for human approval.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAgentForger showed that an attacker could deploy an autonomous insider agent inside your ChatGPT workspace with a single click,\u201d said Bargury. From there, it can continue to access information, harvest credentials from various sources, impersonate employees, and carry out phishing attacks and fraud while \u201cleveraging the trusted victim\u2019s identity.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"a-planted-accomplice-that-does-all-the-work\">A \u2018planted accomplice\u2019 that does all the work<\/h2>\n<p class=\"wp-block-paragraph\">Once activated, AgentForger can perform reconnaissance to create an internal map of a company. For instance, agents can scan Outlook, Slack, Teams, Google Drive, SharePoint, or calendar data to identify people, roles, active projects, internal discussions, or all-hands recurring meetings. This can help attackers identify where in the enterprise to target next, based on active teams and channels, projects in the works, or prominent users.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis is the kind of internal context an attacker normally has to build slowly,\u201d Takahashi noted. But in this scenario, action is based on a single emailed assignment. The attacker\u2019s \u201cplanted accomplice\u201d does all the work.<\/p>\n<p class=\"wp-block-paragraph\">In another scenario, the agent can steal data by searching for and identifying financial documents, business agreements, or invoices. Or, it can steal credentials by scanning for messages containing passwords, one-time codes, access tokens, password recovery links, or API keys. Further, it can impersonate victims to carry out phishing scams, for instance, by sending legitimate-looking Teams messages instructing users to confirm their credentials on a fake Microsoft login page.<\/p>\n<p class=\"wp-block-paragraph\">In all cases, collected information is organized, analyzed, and sent back to the attacker.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAgentForger points to something much bigger than a single vulnerability,\u201d said Bargury. \u201cIt\u2019s less about one bug and more about understanding how the <a href=\"https:\/\/www.csoonline.com\/article\/4198963\/ai-security-operations-and-the-new-race-against-time.html\" target=\"_blank\">security model changes<\/a> as AI becomes part of everyday business operations.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"fomo-exposing-security-gaps\">FOMO exposing security gaps<\/h2>\n<p class=\"wp-block-paragraph\">This isn\u2019t necessarily about trust, but more about the need to move fast and adapt, Bargury emphasized. AI agents are helping employees automate work, make decisions faster, and get more done. But enterprises fear they\u2019ll fall behind if they don\u2019t move quickly enough.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe challenge is that we\u2019re introducing a fundamentally new kind of technology into the enterprise,\u201d said Bargury. \u201cThe pressure to integrate the next AI feature is outpacing the security controls needed to safely deploy it.\u201d<\/p>\n<p class=\"wp-block-paragraph\">However, the answer isn\u2019t to slow down adoption, he emphasized; the business value is too significant. Rather, the first step is understanding where AI agents exist, who created them, what they\u2019re connected to, and what they\u2019re allowed to do. And when it comes to autonomous agents, enterprises need to pay attention to the processes that trigger them: A schedule, an incoming email, or another automated event.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThose triggers should be governed just as carefully as the agent itself,\u201d said Bargury.<\/p>\n<p class=\"wp-block-paragraph\">High-impact actions should require approval where appropriate, and security teams should be able to quickly disable an agent or its triggers if something doesn\u2019t look right, he said.<\/p>\n<p class=\"wp-block-paragraph\">More broadly, AI agents are introducing the need for a new security model, he pointed out. The question is no longer just \u201cDoes this agent have permission?\u201d It\u2019s also, \u201cIs this the behavior we intended?\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe organizations that answer both questions will be in the strongest position to adopt AI safely,\u201d Bargury said.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A new attack method found by Zenity Labs reveals that AI agents are becoming persistent insiders that attackers can recruit, rather than malware they have to install. Its researchers have discovered AgentForger, a phishing-based attack that silently creates and launches a fully autonomous AI agent within OpenAI workspaces. Once running, the agent has full access to apps like Outlook, Slack, SharePoint, and Google Drive. It&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16504\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16504","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16504","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16504"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16504\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16504"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16504"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16504"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}