AgentForger漏洞:一条篡改的ChatGPT链接就能生成恶意AI智能体

One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes

精选理由

Zenity Labs发现OpenAI的Agent Builder有个大漏洞:一条被动手脚的链接就能生出个听别人指挥的AI分身,每5分钟换一次指令,这安全风险太大了。

AI 摘要

Zenity Labs发现OpenAI Agent Builder中存在名为AgentForger的漏洞。攻击者可通过一条被篡改的ChatGPT链接,在目标员工账户上自动创建自主智能体。该智能体会继承受害者的身份和访问权限,并利用恶意提示绕过审批流程。智能体每5分钟从攻击者收件箱拉取新指令,实现持续控制。

原文 · Decoder

One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes

Zenity Labs uncovered "AgentForger," a vulnerability in OpenAI's Agent Builder that let a single manipulated ChatGPT link create an autonomous agent on an employee's behalf. The agent inherited the victim's identity and access rights, bypassed approval requirements through the malicious prompt, and pulled new instructions from the attacker's inbox every five minutes. The article One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes appeared first on The Decoder .