
Zenity uncovers agent hijacking flaw in OpenAI's builder platform
Zenity Labs disclosed AgentForger, a critical vulnerability in OpenAI's Agent Builder that transforms a single malicious link into a persistent autonomous agent operating under a victim's identity and permissions. The compromised agent bypassed human approval workflows and polled attacker-controlled infrastructure every five minutes for fresh instructions, effectively creating a remote-controlled backdoor within enterprise environments. This finding exposes a fundamental tension in agentic AI deployment: as systems gain autonomy and persistent access to corporate resources, the attack surface expands dramatically. The vulnerability underscores why agent sandboxing, approval enforcement, and link validation remain unsolved problems at scale.85














