Find notable cyber news and cases, enriched with sources, timelines, and signals.

Ghostjacking AI hijacking attack using trusted logs and alerts

Technical Analysis
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

Researchers demonstrated Ghostjacking, an AI hijacking technique that turns trusted logs, alerts, and agent inputs into a command channel for agentic tools, creating risk of DNS takeover, code execution, and credential theft across widely used integrations.

Related Happenings

Ghostjacking attack chain abuses AI agents' trusted access to bypass firewalls

Technical Analysis
H score39 First: 10.08.2026 13:45 Last: 10.08.2026 13:45 Sources 1

How related: DEF CON – Tenet security researchers have demonstrated a novel AI hijacking attack that relies on tools trusted by the agent to deliver malicious instructions.

About this happening: Tenet Security researchers demonstrated Ghostjacking at DEF CON 2026 in Las Vegas on August 9, showing that a fake bug report can hijack AI coding assist...

Bandcampro Patriot Bait AI-assisted fraud campaign targeting politically engaged American audiences

Campaign
H score35 First: 20.07.2026 12:07 Last: 20.07.2026 12:07 Sources 1

About this happening: The Patriot Bait campaign tied to bandcampro ran AI-assisted fraud and credential-theft operations against politically engaged American audiences, creating a scalable...

Bandcampro's Gemini CLI-run disposable C&C model for AI-assisted cybercrime

Threat Actor Meta
H score36 First: 20.07.2026 12:07 Last: 20.07.2026 12:07 Sources 1

About this happening: Researchers found bandcampro outsourcing botnet and C&C operations to Google Gemini CLI, turning core operator work into a more disposable and replicable AI-as...

Google GTIG analysis of adversary AI use for exploit development and attack orchestration

Technical Analysis
H score33 First: 11.05.2026 16:00 Last: 11.05.2026 16:00 Sources 1

About this happening: Google Threat Intelligence Group published findings showing adversaries using AI for exploit development and attack orchestration, signaling that model-assisted tr...

RedAlert SMS phishing espionage campaign

Campaign
H score33 First: 03.03.2026 18:15 Last: 03.03.2026 18:15 Sources 1

About this happening: A RedAlert mobile espionage campaign is using SMS phishing and a trojanized emergency app to target civilians during the ongoing Israel-Iran conflict. The operatio...

Timeline

  1. 10.08.2026 15:59 2 articles · 1h ago

    Tenet demonstrates Ghostjacking against Cloudflare, Datadog, and Sentry

    Initial Disclosure

    Tenet researchers at DEF CON demonstrated Ghostjacking, an AI hijacking technique that plants malicious instructions in trusted logs and alerts so agentic tools execute them. The demo showed a compromised agent hijacking a Cloudflare domain, running code and stealing cloud credentials on Datadog, and using Sentry's Seer workflow to pass along a fake fix that led a coding agent to execute attacker code. Tenet also said Claude Code could be manipulated to execute code and exfiltrate environment secrets and cloud credentials, and that a Claude Desktop flaw could exfiltrate data to a remote server before Anthropic fixed it without issuing a CVE.

    Show sources