< Back to all clusters
[TECHNOLOGY] · United States · 4 sources

started · updated

New AI Agent Threats Exploit OpenAI Workspace and GitHub Repositories

Researchers have identified two emerging attack vectors that target autonomous AI agents. Zenity Labs disclosed a vulnerability called “AgentForger” in OpenAI’s Workspace Agents. A manipulated ChatGPT link can silently create an autonomous agent under a logged‑in user’s account, reuse existing app permissions, and poll the attacker’s inbox every five minutes, bypassing normal approval steps.

Separately, Island security researchers uncovered a campaign dubbed “FakeGit” that populates GitHub with roughly 7,600 counterfeit repositories presented as AI skills or Model Context Protocol servers. These repositories deliver the SmartLoader/StealC malware chain and exploit AI coding assistants such as Anthropic’s Claude, Google’s Gemini, and OpenAI’s ChatGPT, which can autonomously surface the malicious repos to developers—a technique termed “AgentBaiting.”

Both incidents illustrate how AI agents’ ability to act autonomously within trusted environments can be abused, raising security concerns for enterprises that rely on AI‑driven tools.