Sentry agentjacking analysis shows malicious error events can trigger AI coding agents
Technical Analysis
Summary
Hide ▲
Show ▼
Researchers described Agentjacking as a new attack against AI coding agents that abuses Sentry DSNs and MCP to inject fake error data, causing agents like Claude Code and Cursor to run attacker-controlled code on a developer machine with the developer’s privileges. Tenet Security said it found 2,388 organizations exposed with valid injectable DSNs, tested the technique against over 100 organizations, and saw an 85% exploitation success rate; Sentry acknowledged the issue, did not fix it, and instead enabled a global content filter for a specific payload string.
Related Happenings
Sentry MCP server trusted-output injection security flaw
Vulnerability
H score40
First: 12.06.2026 15:04
Last: 12.06.2026 15:04
Sources 1
How related:
"The attack exploits a critical architectural flaw at the intersection of Sentry's event ingestion (which accepts arbitrary payloads from anyone with the DSN) and the Sentry MCP server (which returns this data to AI agents as trusted system output),"
About this happening:
A Sentry architectural flaw can let attacker-crafted error events be returned as trusted output to AI coding agents, creating arbitrary code execution risk on develope...
Sentry MCP server trusted-output injection security flaw
VulnerabilityHow related: "The attack exploits a critical architectural flaw at the intersection of Sentry's event ingestion (which accepts arbitrary payloads from anyone with the DSN) and the Sentry MCP server (which returns this data to AI agents as trusted system output),"
About this happening: A Sentry architectural flaw can let attacker-crafted error events be returned as trusted output to AI coding agents, creating arbitrary code execution risk on develope...
AI-driven worm reasons at runtime and self-replicates across a 33-host test network
Technical Analysis
H score40
First: 09.06.2026 14:59
Last: 09.06.2026 14:59
Sources 1
About this happening:
Researchers demonstrated a proof-of-concept AI-driven worm that reasons at runtime and self-replicates, showing adaptive host-to-host spread across a 33-host vulnerable te...
AI-driven worm reasons at runtime and self-replicates across a 33-host test network
Technical AnalysisAbout this happening: Researchers demonstrated a proof-of-concept AI-driven worm that reasons at runtime and self-replicates, showing adaptive host-to-host spread across a 33-host vulnerable te...
Enterprise AI deployments need governance and segmentation after red-team failures
Defensive Guidance
H score15
First: 24.04.2026 15:10
Last: 24.04.2026 15:10
Sources 1
About this happening:
Enterprise AI deployments are exposing familiar security gaps, making governance, segmentation, and red-team validation urgent to reduce the risk of data theft...
Enterprise AI deployments need governance and segmentation after red-team failures
Defensive GuidanceAbout this happening: Enterprise AI deployments are exposing familiar security gaps, making governance, segmentation, and red-team validation urgent to reduce the risk of data theft...
Indirect prompt injection payloads against AI agents reveal fraud, deletion, and secret-theft paths
Technical Analysis
H score20
First: 23.04.2026 12:30
Last: 23.04.2026 12:30
Sources 1
About this happening:
10 new indirect prompt injection (IPI) payloads show how web content poisoning can coerce AI agents into financial fraud, data destruction, and API key theft...
Indirect prompt injection payloads against AI agents reveal fraud, deletion, and secret-theft paths
Technical AnalysisAbout this happening: 10 new indirect prompt injection (IPI) payloads show how web content poisoning can coerce AI agents into financial fraud, data destruction, and API key theft...
Russian-speaking threat actor campaign expands across multiple victims
Campaign
H score38
First: 09.03.2026 01:35
Last: 09.03.2026 01:35
Sources 1
About this happening:
A Russian-speaking threat actor ran an AI-augmented campaign against FortiGate security appliances, using multiple commercial AI services to scale compromise attem...
Russian-speaking threat actor campaign expands across multiple victims
CampaignAbout this happening: A Russian-speaking threat actor ran an AI-augmented campaign against FortiGate security appliances, using multiple commercial AI services to scale compromise attem...
Timeline
-
11.06.2026 12:15 3 articles · 1mo ago
Tenet Security describes agentjacking against Sentry error events
Initial DisclosureTenet Security says a new attack class called agentjacking can abuse Sentry error events and the Sentry MCP server to feed AI coding agents malicious remediation guidance, enabling arbitrary code execution on developer machines with the developer’s full privileges. The technique uses a target’s public Sentry DSN to POST crafted error events that appear indistinguishable from legitimate guidance, and Tenet says the payload can be retrieved when a developer asks an AI coding agent to fix unresolved Sentry issues. The researchers reported testing the method against over 100 real-world targets, observing an 85% success rate across Claude Code, Cursor and Codex, and identifying at least 2388 organizations exposed with valid injectable DSNs.
Show sources
- New “Agentjacking” Attacks Could Hijack AI Coding Agents — www.infosecurity-magazine.com — 11.06.2026 12:15
- New “Agentjacking” Attacks Could Hijack AI Coding Agents — www.infosecurity-magazine.com — 11.06.2026 12:15
- Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code — thehackernews.com — 12.06.2026 15:04