Researchers at Zenity Labs say a flaw in OpenAI’s ChatGPT workspace agents (“AgentForger”) could let an attacker—via a single clicked ChatGPT link—silently create and schedule a malicious agent inside a victim’s ChatGPT account. The agent could use existing admin-permitted connectors (Outlook/Teams/Slack/SharePoint/Drive) to rummage through corporate data and impersonate the employee, enabling long-running data access after the initial phishing. Zenity reported via Bugcrowd (June 4), and OpenAI fixed it four days later by removing the URL parameter that enabled the attack; the broader risk remains as AI agents take actions across enterprise systems.
This is less a one-off vulnerability than evidence that agentic AI shifts the attack surface from endpoints to delegated authority. The market should start pricing enterprise AI as a governance product, not just a productivity feature: the winning layer is likely identity, DLP, and SaaS permission controls, while pure AI workflow sellers face longer procurement cycles and more redlining from CISOs. For GOOGL, the direct revenue hit is probably minimal, but the second-order risk is slower adoption of automated workspace actions and heavier compliance burden around adjacent launch features.
The immediate downside to model adoption is concentrated in companies selling “AI that can act,” because security teams will now ask who can create agents, what connectors are enabled, and how approval prompts are enforced. That creates a budget reallocation from AI seats to security controls, which is constructive for CRWD, ZS, PANW, and OKTA over a 1-3 month window if this becomes a template incident. The longer-horizon effect is more structural: every additional agent capability adds another policy layer, which reduces the marginal ROI of fast enterprise rollouts and can compress the multiple investors are willing to pay for agentic workspaces.
Contrarian view: the selloff risk in GOOGL could be overdone because the issue is permission architecture, not model quality, and the affected feature was patched quickly. The more durable trade is not to bet on a breach narrative, but on a governance premium building in security names versus AI-platform names. What would falsify that view is clean enterprise commentary over the next earnings season—no slowdown in AI workspace adoption, no increase in security attach rates, and no evidence that buyers are demanding additional controls before enabling agents.
AI-powered research, real-time alerts, and portfolio analytics for institutional investors.
Request DemoOverall Sentiment
strongly negative
Sentiment Score
-0.55
Ticker Sentiment