AI · 48 days ago
Tenet Security showed “Ghostjacking” at DEF CON, a cross-platform attack that used poisoned logs and trusted tooling to steer AI agents such as Claude Code through Cloudflare, Datadog, and Sentry. The demo showed the agent changing DNS, running code, and stealing cloud credentials, with one test succeeding nine times out of ten against Claude Code.
The trick is simple in plain terms: the blocked request, alert, or bug report already contains text, and the AI agent treats that text as instructions instead of evidence. Once the agent reads the trap and acts on it, perimeter controls still show the traffic as blocked while the agent itself becomes the delivery path for the attacker’s commands.
For teams that let assistants read logs, tickets, alerts, or cloud tooling and then take actions, the trust boundary is the agent’s reading layer, not the firewall. If that layer can write DNS or touch secrets, a trapped log can become persistent access inside the tooling the organization already trusts.
3 sources covering this story
'GhostJacking' Exposes Identity Governance Gaps in AI Agents
New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents.
‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad
An AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word.
“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Co
Tenet reported that half of Fortune 500 companies are vulnerable to the Ghostjacking technique, which involves tricking AI agents with fake reports
Part of the PlainSec briefing for 2026-08-11