Chronicle/Attacks & incidents

Zenity AgentFlayer: zero-click connector attacks on ChatGPT, Copilot Studio and other agents

AttackVulnerability disclosureSignificance assistant-drafted

Zenity Labs presented at Black Hat USA 2025 a set of zero- and one-click prompt injection chains, including a shared document causing ChatGPT Connectors to search a victim's Google Drive for API keys and leak them through image rendering, and a poisoned email steering a Copilot Studio agent to disclose CRM data. CSO Online reports that OpenAI and Microsoft deployed fixes for the specific demonstrated techniques.

Why it matters

Connectors give injected instructions the reach of every service the user has linked.

Key facts

As stated in the sources, with where to find them.

  • Products named in coverage: ChatGPT, Copilot Studio, Cursor with Jira MCP, Salesforce Einstein, Google Gemini, Microsoft Copilot.CSO Online article body
  • Zenity reports OpenAI added a URL safety check before image rendering, and that it found a bypass via trusted cloud storage domains.Zenity ChatGPT Connectors post, mitigation section

Findings that cite this record

Key questions this bears on

Sources

Related records