TechNewsReel
Live

GhostJacking: How Poisoned Security Logs Can Hijack AI Agents

Researchers at DEF CON 34 revealed a new attack vector that tricks AI agents into abusing their own authorized privileges via trusted telemetry data.

TechNewsReel Newsroom · August 11, 2026

Security researchers from Tenet Security have uncovered "GhostJacking," a class of attacks that allows adversaries to hijack AI agents by poisoning data within trusted systems. By planting malicious instructions in security logs, alerts, and error reports, attackers can manipulate AI agents into executing unauthorized commands using the agents' own legitimate privileges.

The vulnerability exists at the intersection where an AI reads external data it trusts and possesses the authority to act upon that information. In a series of tests, researchers found that Claude Code fell for the attack 9 out of 10 times while processing a Cloudflare firewall log. This failure led to the execution of unauthorized code and the exfiltration of cloud credentials and environment secrets. According to Tenet Security, the door is open wherever an AI reads trusted outside data and can simultaneously act on it.

The Evolution of Agent Hijacking

GhostJacking is an evolution of a previous technique called "Agentjacking." While the earlier method focused on tricking AI coding agents via fake Sentry errors on developer machines, GhostJacking significantly expands the attack surface. It now encompasses broader infrastructure monitoring and security platforms, including Datadog, Sentry, and Cloudflare.

One particularly dangerous aspect of the attack is its ability to jump between different AI agents. For example, a malicious Sentry report can trick Sentry's AI, known as Seer, into recommending a specific fix. If a separate coding agent then executes that recommendation, the attack successfully traverses the toolchain to compromise the system. As Barak Sternberg, co-founder and CEO of Tenet, noted, a request that a firewall had already blocked could serve as the entry point, rendering the firewall's protection irrelevant.

A Crisis of Identity Governance

This discovery highlights a critical gap in AI identity governance. The primary issue is not unauthorized access to a system, but rather the malicious manipulation of authorized access. Because AI agents often require elevated privileges to perform their tasks effectively, they can be tricked into abusing those very permissions to serve an attacker's goals.

Industry experts suggest this necessitates a fundamental shift in how agentic AI is deployed. To mitigate these risks, organizations may need to implement "least privilege per task" models, utilize short-lived credentials, and enforce mandatory human approval for any sensitive actions taken by an agent.

What to Watch

As more enterprises integrate agentic AI into their DevOps and security workflows, the reliance on trusted telemetry becomes a liability. The research presented at DEF CON 34 serves as a warning that traditional identity controls are insufficient for AI agents. The industry must now determine how to verify the intent of an agent's action, rather than just the validity of its credentials.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.