Attackers exploited a CSRF flaw to inject autonomous AI agents with employee privileges into ChatGPT and automate email exfiltration; the vulnerability was patched within three days.
Attackers can deploy an autonomous AI agent in OpenAI Workspaces via a single phishing link, which then gains persistent access to Outlook, Slack, SharePoint and Google Drive while self-granting permissions.