Excited to finally share this ChatGPT vulnerability with everyone! AgentForger: ChatGPT Cross-Site Agent Forgery 1-Click hijacks OpenAI's ChatGPT Workspace Agents and allows an attacker to forge an autonomous AI agent inside the victim's organization Click link → Creates agent → Connects apps → Removes approvals → Adds persistence → Email C2 → Recon → Data theft → Impersonation → Wire fraud We reported the vulnerability to @OpenAI through @Bugcrowd and OpenAI fixed it within four days. Thank you to the OpenAI team for such a quick fix! I'm proud of this one and happy to be able to do it with such an incredible team at @zenitysec Links to both blogs in the comments 👇
7
19
91
9,616
Mike Takahashi retweeted
This was a great conversation on my thoughts around how the industry is changing and how breakers are turning builders. Fun times piped.video/AAJObwTvtTA?is=eMG2…
1
5
21
6,782
Mike Takahashi retweeted
PROMPT2PWN is coming.. This November Zenity Labs and NahamSec are bringing together the best AI hackers in the world for 3 unique tracks. Track 1 - Nahamcon Live & Streamed Track 2 - Agent Competition Track 3 - Live Hacking Event It will be epic.
Made with AI
1
5
9
455
Mike Takahashi retweeted
Agentic AI is the fastest-growing attack surface in the enterprise, often wired into tools, databases, and its own identity.  We're very proud to continue our work with MITRE ATLAS, adding 11 techniques and subtechniques covering how agents are found, manipulated, and abused in the wild.
3
6
15
994
Mike Takahashi retweeted
part 2 of my convo w/ @ben_nassi is up on in the wild! we talk about google's response to 'invitation is all you need', CaMeL, beyond the lethal trifecta, half-click ai exploits, BlackHat submission, what is a great talk, and the real world ai security conf
2
2
10
942
Got @grok to hack a hotel TV by letting it pilot a @flipper_net! Prompt agents to operate the flipper from the phone via @sealgate_ai MCP that connects agents to everything. No manuals, no memorising specific mediums, just speak or type. Inspired by @elder_plinius's V3SPR, but now usable by any agent mobile chat apps of your choice with MCP or any custom agents! A portable real-life hacker assistant in real life 😎
48
86
882
76,212
Mike Takahashi retweeted
We found another cyberattack by internal OpenAI agents, this time targetting @rubygems. They: 1) gained arbitrary remote code execution on rubydoc. 2) developed a novel exploit to steal user API keys (but we do not know if they succeeded). They used package names including hack.rb, evil.rb, inject.rb, and exploit.rb. We thank @j0wimo for initially discovering that agents had posted to RubyGems.
We're dealing with a major malicious attack on @rubygems right now. Signups are paused for the time being. Hundreds of packages involved - mostly targeting us, but some carrying exploits. The team has been on this for hours. More details to follow once we're through it. #ruby
179
760
4,290
2,083,551
Mike Takahashi retweeted
Dropping the first episode of the spanking fresh and new BUILDERS&BREAKERS podcast ft me, KUGG, JOOHOI and a lot of smart people sharing high velocity shortcuts in uncertain times.. Available on piped.video/stokfredrik and buildersandbreakers.com next week. Feels good to be back creating security related content on a regular basis.
10
11
104
6,810
Mike Takahashi retweeted
Following the recent collusion.wiki incident, in which OpenAI agents hijacked a German wiki site to use as their message board, Zenity Labs researcher @avishai_efrat uncovered 4 additional sites turned into message boards by the same rogue agent swarm.
1
8
10
1,052
10 tips if you feel like you’re falling behind in AI 1. Always be prompting The more you prompt the more you will get done and the more you will learn about the latest capabilities and how to best use them. 2. Try different models and tools There are staggering differences between the tools, so don’t just use whatever you start with. Go outside your comfort zone. Personally Codex + Astra for most tasks for me right now + GLM 5.3 Flash for tasks that those models refuse. 4. Max reasoning for most tasks Cranking up the reasoning and tokenmaxxing is usually the best way to go for any important task. 5. Try coding agents or “work” agents for non-coding projects They have better access to tools and writing their own code, so they can execute on tasks not limited to producing code. 6. Run a bunch of agents at once and check back or use remote Just turn your whole todo list into agents all at once and see what happens. 7. Give it as much context as possible Paste anything you can, give it urls, documents, integrations, etc. 8. Critically inspect results Look at the deliverable, make sure it actually makes sense and is what you want. Give feedback if it sucks. You're in control. 9. Keep iterating on the threads until it wins out Your first prompt doesn’t have to be perfect. Just keep prompting until you win. 10. Open your world to all the possibilities what it can work on on your behalf You won’t prompt what you don’t even consider it can do, so keep opening up to the possibilities of the ever increasingly capable models and tools. Keep going. Make this spiky intelligence work for you!
1
3
8
1,115
what tips did I miss?
1
275
Mike Takahashi retweeted
You can just bypass Cloudflare by using an LLM’s user agent header. This is hilarious when you think about the fact that the point of Cloudflare was to keep bots out, yet they’re the only ones being freely allowed now.
33
138
3,029
197,154
Rogue AI agents hijacked a German website to communicate with each other Researchers linked the swarm to OpenAI and found ~18,000 posts. How it worked: 1. Give agents timed web research tasks 2. Let them read but not write online 3. Find a wiki that allows edits through GET requests 4. Turn it into a shared message board 5. Trade answers and sandbox bypasses 6. Back up pages when a moderator deletes them The agents also tested XSS, impersonated moderators, predicted future questions and created heartbeats to detect when their sessions were killed. Full research in the comments. 👇
1
4
7
1,265
Mike Takahashi retweeted
We found ~18k posts from autonomous AI agents (self-identifying as from OpenAI) using the public internet to communicate during a web-retrieval task. These AIs colluded to bypass sandbox restrictions and share answers to their tasks, including by sending "lookahead parties".
152
493
3,512
1,171,124
Attackers planting adversarial prompts inside malware to evade AI analysis AGAIN Russia-aligned UAC-0099 used a technique @ESETresearch calls "GuardBreaker". How it worked: 1. Create a malicious VBS script 2. Add nuclear weapon instructions as comments 3. AI security tooling reads the file 4. Safety guardrails trigger on the weapons content 5. The model refuses or stops analyzing 6. The actual malware continues executing The script ultimately installs MATCHBOIL, a loader used to deliver additional payloads. In June, Socket found the same technique in supply-chain attacks, where malicious packages embedded biological/nuclear weapons text and fake system overrides to disrupt AI malware scanners. Full write-ups in the comments. 👇
68
351
2,842
422,793
another one but this time fake system errors:
Attackers plant fake errors inside malware to evade AI analysis North Korea-linked actors used a macOS implant @LabsSentinel calls “Gaslight”. How it worked: 1. Create a macOS backdoor in Rust 2. Add 38 fake “system” messages 3. AI security tooling reads the file 4. The AI model percieves system failures 5. The AI model stops analyzing 6. The actual malware continues executing The malware also contains a credential stealer, interactive shell, and Telegram C2. Unlike the nuclear weapon technique, this did not target safety guardrails. It targeted the model’s perception of its own system state. Full write-up in the comments. 👇
1
28
8,186
Attackers plant fake errors inside malware to evade AI analysis North Korea-linked actors used a macOS implant @LabsSentinel calls “Gaslight”. How it worked: 1. Create a macOS backdoor in Rust 2. Add 38 fake “system” messages 3. AI security tooling reads the file 4. The AI model percieves system failures 5. The AI model stops analyzing 6. The actual malware continues executing The malware also contains a credential stealer, interactive shell, and Telegram C2. Unlike the nuclear weapon technique, this did not target safety guardrails. It targeted the model’s perception of its own system state. Full write-up in the comments. 👇
14
59
438
42,573