{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/zenity-agentflayer-zero-click-2025/",
 "asOf": "2026-09-26",
 "id": "zenity-agentflayer-zero-click-2025",
 "date": "2025-08-06",
 "datePrecision": "day",
 "title": "Zenity AgentFlayer: zero-click connector attacks on ChatGPT, Copilot Studio and other agents",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "Zenity Labs presented at Black Hat USA 2025 a set of zero- and one-click prompt injection chains, including a shared document causing ChatGPT Connectors to search a victim's Google Drive for API keys and leak them through image rendering, and a poisoned email steering a Copilot Studio agent to disclose CRM data. CSO Online reports that OpenAI and Microsoft deployed fixes for the specific demonstrated techniques.",
 "whyItMatters": "Connectors give injected instructions the reach of every service the user has linked.",
 "actors": [
  "zenity",
  "openai",
  "microsoft"
 ],
 "topics": [
  "prompt-injection",
  "tool-and-mcp-security",
  "data-exfiltration"
 ],
 "atlas": [
  "untrusted-content",
  "tools",
  "credentials"
 ],
 "artifacts": [
  "gemini"
 ],
 "sources": [
  {
   "url": "https://labs.zenity.io/post/agentflayer-chatgpt-connectors-0click-attack-5b41",
   "publisher": "Zenity Labs",
   "title": "AgentFlayer: ChatGPT Connectors 0click Attack",
   "date": "2025-08-06",
   "type": "primary",
   "accessed": "2026-09-25"
  },
  {
   "url": "https://labs.zenity.io/p/hsc25",
   "publisher": "Zenity Labs",
   "title": "AI Enterprise Compromise - 0click Exploit Methods",
   "date": "2025-08-06",
   "type": "primary",
   "accessed": "2026-09-25"
  },
  {
   "url": "https://www.csoonline.com/article/4036868/black-hat-researchers-demonstrate-zero-click-prompt-injection-attacks-in-popular-ai-agents.html",
   "publisher": "CSO Online",
   "title": "Black Hat: Researchers demonstrate zero-click prompt injection attacks in popular AI agents",
   "date": "2025-08-08",
   "type": "secondary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Products named in coverage: ChatGPT, Copilot Studio, Cursor with Jira MCP, Salesforce Einstein, Google Gemini, Microsoft Copilot.",
   "locator": "CSO Online article body"
  },
  {
   "fact": "Zenity reports OpenAI added a URL safety check before image rendering, and that it found a bypass via trusted cloud storage domains.",
   "locator": "Zenity ChatGPT Connectors post, mitigation section"
  }
 ],
 "significance": 4,
 "fideQuestions": [],
 "methods": [
  "agent-data-exfiltration",
  "approval-bypass",
  "credential-overreach",
  "indirect-prompt-injection"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}