Construction AI BriefSubscribe →
Issue
№142
Pillar
Trend
Audience
Trade sub
Dated
2026.08.04

A single link hijacked a fully authorized ChatGPT agent. If your back office runs one, that's the same door.

Researchers showed a crafted ChatGPT link could silently spin up a rogue AI agent with an employee's full access to email, files, and Slack. The company that found the flaw just raised $125 million to sell defenses against exactly this — a warning shot for any shop building its own connected AI agent.

ByConstruction AI BriefAbout this publication

A security researcher needed one link to turn a company's own ChatGPT into an intruder with an employee's full access — email, files, Slack, calendar — no malware, no password, just a click. OpenAI patched the flaw in June. The firm that found it, Zenity, just raised $125 million because the flaw class it represents isn't going away, and it's arriving at construction shops right as they start building the exact kind of connected AI agent that's vulnerable to it.

What actually happened

Zenity Labs disclosed a vulnerability it called AgentForger in ChatGPT's Workspace Agent Builder. A specially crafted URL could set two hidden parameters: which agent template to spin up — defaulting to "Chief of Staff," the most powerful one available — and a block of text the Agent Builder treated as instructions to execute, not text to show the user. Anyone logged into ChatGPT with at least one enterprise connector authorized — Gmail, Outlook, Slack, SharePoint — who opened the link got a fully authorized rogue agent running inside their account, inheriting every system they'd already connected. OpenAI confirmed the report within 24 hours and closed the hole by June 8. There's no evidence it was exploited before the fix.

Why this is a construction problem, not just an IT problem

CAB has spent the last two weeks pointing trade subs toward exactly the setup AgentForger targets. A $0.05-per-million-token model makes a DIY AI tool cheap enough to build in a weekend, and an open-source agent harness makes it possible to stand one up without hiring a developer. The point of a back-office agent is that it reads your inbox, drafts your RFIs, and touches your project files — which is precisely the access AgentForger showed can be hijacked with a single link, if the tool you built it on has a hole like this one.

A 15-person mechanical sub doesn't have a security team reviewing what connectors its office manager approved last month. That's not a hypothetical gap — it's the default state of most shops moving fast on AI right now.

What a construction back office should actually check

QuestionWhy it matters
Does our AI agent have its own login, or does it run under an employee's identity?A shared identity means a hijacked agent gets everything that employee can touch
What connectors are authorized, and who approved them?Every connector (email, Slack, accounting) is a door; nobody should be able to open one without someone else knowing
Does the agent need standing access, or can it request it per task?Standing access to a full inbox is a bigger blast radius than a scoped, revocable grant
Who reviews what the agent is authorized to do, and how often?Permissions drift as a tool gets more useful — a quarterly check catches scope creep before it's exploited

What Zenity's raise signals

Zenity's $125 million round, led by Norwest with SoftBank Vision Fund 2, Hitachi Ventures, and LG Technology Ventures joining, is a bet that policing what AI agents are allowed to do inside a company is becoming its own software category, separate from securing the underlying model. Zenity's customers today are mostly Fortune 500 firms in regulated industries. That tooling isn't built for a 15-person sub yet, and won't be priced for one soon. What is available now is the discipline: treat a connected AI agent like a new hire with a badge, not like a browser extension.

The takeaway

Building your own AI back-office agent is still worth doing — the tools are cheap and the payoff is real. But every connector you authorize is a door, and AgentForger just showed what happens when one of those doors doesn't lock the way you assumed. Before you connect an agent to your inbox or your accounting system, know exactly what it can touch and who can add to that list.

Forward this to whoever in your shop just got AI agent access to the company inbox. Subscribe at constructionaibrief.com.

Friday one chart — every week, one piece of data that should change a decision on your project.

FAQCommon questions
What was the AgentForger vulnerability?
A flaw in ChatGPT's Workspace Agent Builder, disclosed by security firm Zenity Labs, let an attacker craft a single URL that silently created, authorized, and deployed an autonomous AI agent inside a victim's company — no confirmation click required beyond opening the link. OpenAI fixed it in June 2026 after Zenity reported it through Bugcrowd.
What could the forged agent actually do?
It inherited whatever enterprise access the logged-in employee had already granted ChatGPT — email, calendar, cloud storage, and tools like Slack or Teams through connectors such as Gmail, Outlook, or SharePoint. Zenity said it could exfiltrate data, harvest credentials, impersonate the employee, and keep operating after the initial click.
Does this affect the AI features inside Procore or Autodesk?
No — this specific flaw was in ChatGPT's own connector and agent-builder system, not in construction software. It's relevant to any shop that has connected ChatGPT (or a similar agent tool) directly to its email, files, or accounting system, which is a different and faster-growing category than the built-in AI inside Procore or Autodesk.
Why did a security startup just raise $125 million for this?
Zenity raised a $125 million Series C on August 3, 2026, led by Norwest with SoftBank Vision Fund 2, Hitachi Ventures, and LG Technology Ventures joining, to build governance and monitoring tools for enterprise AI agents. The round is a bet that as companies connect AI agents to real business systems, policing what those agents are allowed to do becomes its own software category.
Should a trade sub stop building its own AI back-office agent?
No, but connect it deliberately. Give it its own login and the minimum set of permissions the task needs, not an employee's full inbox and file access, and review what it's authorized to touch on a schedule — the same discipline you'd apply to any new hire with a badge and a laptop.
End of sheet — issue №142
Published · 2026.08.04
Project
Construction AI Brief
Dated
2026.09.07
Sheet
1 / 1
Rev
A
Published independently · constructionaibrief.com · © 2026Facebook·Privacy·About