Ghostjacking AI hijacking attack using trusted logs and alerts
Technical Analysis
Summary
Hide ▲
Show ▼
Researchers demonstrated Ghostjacking, an AI hijacking technique that turns trusted logs, alerts, and agent inputs into a command channel for agentic tools, creating risk of DNS takeover, code execution, and credential theft across widely used integrations.
Related Happenings
Ghostjacking attack chain abuses AI agents' trusted access to bypass firewalls
Technical Analysis
H score39
First: 10.08.2026 13:45
Last: 10.08.2026 13:45
Sources 1
How related:
DEF CON – Tenet security researchers have demonstrated a novel AI hijacking attack that relies on tools trusted by the agent to deliver malicious instructions.
About this happening:
Tenet Security researchers demonstrated Ghostjacking at DEF CON 2026 in Las Vegas on August 9, showing that a fake bug report can hijack AI coding assist...
Ghostjacking attack chain abuses AI agents' trusted access to bypass firewalls
Technical AnalysisHow related: DEF CON – Tenet security researchers have demonstrated a novel AI hijacking attack that relies on tools trusted by the agent to deliver malicious instructions.
About this happening: Tenet Security researchers demonstrated Ghostjacking at DEF CON 2026 in Las Vegas on August 9, showing that a fake bug report can hijack AI coding assist...
Bandcampro Patriot Bait AI-assisted fraud campaign targeting politically engaged American audiences
Campaign
H score35
First: 20.07.2026 12:07
Last: 20.07.2026 12:07
Sources 1
About this happening:
The Patriot Bait campaign tied to bandcampro ran AI-assisted fraud and credential-theft operations against politically engaged American audiences, creating a scalable...
Bandcampro Patriot Bait AI-assisted fraud campaign targeting politically engaged American audiences
CampaignAbout this happening: The Patriot Bait campaign tied to bandcampro ran AI-assisted fraud and credential-theft operations against politically engaged American audiences, creating a scalable...
Bandcampro's Gemini CLI-run disposable C&C model for AI-assisted cybercrime
Threat Actor Meta
H score36
First: 20.07.2026 12:07
Last: 20.07.2026 12:07
Sources 1
About this happening:
Researchers found bandcampro outsourcing botnet and C&C operations to Google Gemini CLI, turning core operator work into a more disposable and replicable AI-as...
Bandcampro's Gemini CLI-run disposable C&C model for AI-assisted cybercrime
Threat Actor MetaAbout this happening: Researchers found bandcampro outsourcing botnet and C&C operations to Google Gemini CLI, turning core operator work into a more disposable and replicable AI-as...
Google GTIG analysis of adversary AI use for exploit development and attack orchestration
Technical Analysis
H score33
First: 11.05.2026 16:00
Last: 11.05.2026 16:00
Sources 1
About this happening:
Google Threat Intelligence Group published findings showing adversaries using AI for exploit development and attack orchestration, signaling that model-assisted tr...
Google GTIG analysis of adversary AI use for exploit development and attack orchestration
Technical AnalysisAbout this happening: Google Threat Intelligence Group published findings showing adversaries using AI for exploit development and attack orchestration, signaling that model-assisted tr...
RedAlert SMS phishing espionage campaign
Campaign
H score33
First: 03.03.2026 18:15
Last: 03.03.2026 18:15
Sources 1
About this happening:
A RedAlert mobile espionage campaign is using SMS phishing and a trojanized emergency app to target civilians during the ongoing Israel-Iran conflict. The operatio...
RedAlert SMS phishing espionage campaign
CampaignAbout this happening: A RedAlert mobile espionage campaign is using SMS phishing and a trojanized emergency app to target civilians during the ongoing Israel-Iran conflict. The operatio...
Timeline
-
10.08.2026 15:59 2 articles · 1h ago
Tenet demonstrates Ghostjacking against Cloudflare, Datadog, and Sentry
Initial DisclosureTenet researchers at DEF CON demonstrated Ghostjacking, an AI hijacking technique that plants malicious instructions in trusted logs and alerts so agentic tools execute them. The demo showed a compromised agent hijacking a Cloudflare domain, running code and stealing cloud credentials on Datadog, and using Sentry's Seer workflow to pass along a fake fix that led a coding agent to execute attacker code. Tenet also said Claude Code could be manipulated to execute code and exfiltrate environment secrets and cloud credentials, and that a Claude Desktop flaw could exfiltrate data to a remote server before Anthropic fixed it without issuing a CVE.
Show sources
- ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad — www.securityweek.com — 10.08.2026 15:59
- ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad — www.securityweek.com — 10.08.2026 15:59