Ghostjacking Turns AI Telemetry Into Attack Commands
Tenet Security showed “Ghostjacking” at DEF CON, a cross-platform attack that used poisoned logs and trusted tooling to steer AI agents such as Claude Code through Cloudflare, Datadog, and Sentry. The demo showed the agent changing DNS, running code, and stealing cloud credentials, with one test succeeding nine times out of ten against Claude Code.
The trick is simple in plain terms: the blocked request, alert, or bug report already contains text, and the AI agent treats that text as instructions instead of evidence. Once the agent reads the trap and acts on it, perimeter controls still show the traffic as blocked while the agent itself becomes the delivery path for the attacker’s commands.
For teams that let assistants read logs, tickets, alerts, or cloud tooling and then take actions, the trust boundary is the agent’s reading layer, not the firewall. If that layer can write DNS or touch secrets, a trapped log can become persistent access inside the tooling the organization already trusts.