
A single ChatGPT link was enough to slip in an infiltrated AI agent with your employee permissions
🕒 Published on Zendoric: July 25, 2026 · 00:23
Zenity Labs found a flaw in ChatGPT's agent builder that allowed, with a single click on a seemingly innocuous link, the creation of an autonomous agent with the victim's full access to Outlook, Teams, Slack or SharePoint. OpenAI fixed it in four days, but the case foreshadows a structural problem: agents that act as employees need security controls that almost no one has today.


























