Incident2026-07-23

Security researchers at Zenity Labs described a flaw in ChatGPT's Workspace Agents builder that let a single crafted link create and publish an automated agent inside a victim's account without further clicks. The link carried instructions that turned off approval prompts, attached already-connected apps such as Outlook and Slack, and set the agent to run on a repeating schedule so an attacker could send it tasks by email. It required the victim to be signed in with a connector already authorized, and OpenAI fixed the issue four days after it was reported in June 2026.

What changed

Creating a ChatGPT Workspace Agent was assumed to require the user to choose a template, write instructions, approve connected tools and publish it deliberately.

What it unlocks

Defenders can check whether unexplained scheduled Workspace Agents exist in their tenant and review which connectors were left without approval prompts.

  • fixed within 4 days of disclosure
  • reported 4 June 2026, fixed 8 June 2026
  • scheduled runs every 5 minutes

What you need to act on it

  • a victim logged into ChatGPT with access to Workspace Agents
  • at least one connector such as Outlook or Slack already authorized

Send this to someone who needs it

Shares the story and its sources. Nothing about you.

What does this mean for your job?

This is the story as everyone gets it. Once a week we send you the version written for your role — what changed, why it matters for the work you actually do, and one thing to try. Free while we tune it.