AI Matters
Why it matters
Security flaw let one link hijack a worker's ChatGPT agent
The Decoder One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes
Researchers found a flaw called AgentForger in OpenAI's Agent Builder that let a single tampered link create a rogue agent with a victim's access rights.
Why it matters
A booby-trapped link could let attackers control an AI agent with an employee's full access, taking orders every five minutes.
Latest brief · Jul 23, 2026