The Workspace Agents tool, which OpenAI introduced as a new feature for ChatGPT in April of this year, allows teams to create AI agents to handle recurring tasks.
But the system apparently offers a gateway for cybercriminals. They can easily sneak into the system and create an agent who then smuggles internal information to the outside world.
Clicking on the fake ChatGPT link is enough
AI security firm Zenity Labs discovered the vulnerability in ChatGPT and described it in a blog post. According to security researchers, all it takes is a fake ChatGPT link clicked on by a member of a team to infiltrate the system.
Top Article
${content}
${custom_anzeige-badge}
${custom_tr-badge}
${section}
${title}
In the name of this team member, a malicious actor can then create an agent that acts in his interests and, for example, accesses sensitive data. Once activated, the double agent does so not just once, but repeatedly, according to a rhythm that the attacker can set. The agent can be instructed to check incoming emails every five minutes.
AgentForger as a perfidious further development of CSRF
Zenity Labs has named the mechanism by which malicious actors can infiltrate enemy agents AgentForger. This is a further development of what is already known Cross-Site-Request-Forgery (CSRF).
With a conventional one CSRF, attackers can only foist a single fake request on their victims. But an AgentForger can create an agent that does this over and over again.
The fake agent can access existing authorizations. The unsuspecting users do not see an OAuth consent screen. The fake URL instructs the system never to ask for approval.
OpenAI has closed a security hole
Zenity Labs reported the vulnerability to OpenAI in early June. Apparently a single parameter that was set too freely was to blame. Four days later, the company had plugged the gap. It is not known whether a real cybercriminal has ever exploited the security hole.
Local AI: No problem with these 5 tools
Local AI: No problem with these 6 tools
