Ghostjacking attack chain abuses AI agents' trusted access to bypass firewalls
Technical Analysis
Summary
Hide ▲
Show ▼
Tenet Security researchers demonstrated Ghostjacking at DEF CON 2026 in Las Vegas on August 9, showing that a fake bug report can hijack AI coding assistants through trusted logs and alerts. The attack was shown against Cloudflare, Datadog, and Sentry, where it could drive DNS changes, code execution, and cloud credential theft in demo scenarios. Tenet said the technique worked 9 times out of 10 against Claude Code on Cloudflare’s recommended setup, and that a related Claude Desktop flaw could exfiltrate data; Anthropic fixed that flaw without issuing a CVE.
Related Happenings
Ghostjacking AI hijacking attack using trusted logs and alerts
Technical Analysis
H score30
First: 10.08.2026 15:59
Last: 10.08.2026 15:59
Sources 1
How related:
DEF CON – Tenet security researchers have demonstrated a novel AI hijacking attack that relies on tools trusted by the agent to deliver malicious instructions.
About this happening:
Researchers demonstrated Ghostjacking, an AI hijacking technique that turns trusted logs, alerts, and agent inputs into a command channel for agentic tools, creating risk...
Ghostjacking AI hijacking attack using trusted logs and alerts
Technical AnalysisHow related: DEF CON – Tenet security researchers have demonstrated a novel AI hijacking attack that relies on tools trusted by the agent to deliver malicious instructions.
About this happening: Researchers demonstrated Ghostjacking, an AI hijacking technique that turns trusted logs, alerts, and agent inputs into a command channel for agentic tools, creating risk...
Bandcampro's Gemini CLI-run disposable C&C model for AI-assisted cybercrime
Threat Actor Meta
H score36
First: 20.07.2026 12:07
Last: 20.07.2026 12:07
Sources 1
About this happening:
Researchers found bandcampro outsourcing botnet and C&C operations to Google Gemini CLI, turning core operator work into a more disposable and replicable AI-as...
Bandcampro's Gemini CLI-run disposable C&C model for AI-assisted cybercrime
Threat Actor MetaAbout this happening: Researchers found bandcampro outsourcing botnet and C&C operations to Google Gemini CLI, turning core operator work into a more disposable and replicable AI-as...
Defensive guidance for splitting behavioral detections around AI coding agents on Windows endpoints
Defensive Guidance
H score28
First: 08.07.2026 20:02
Last: 08.07.2026 20:02
Sources 1
About this happening:
AI coding agents on Windows endpoints are triggering attacker-style detections, forcing defenders to separate benign automation from real credential theft risk. A June 2...
Defensive guidance for splitting behavioral detections around AI coding agents on Windows endpoints
Defensive GuidanceAbout this happening: AI coding agents on Windows endpoints are triggering attacker-style detections, forcing defenders to separate benign automation from real credential theft risk. A June 2...
Major U.S. services company hit by ransomware attack linked to DragonForce
Incident
H score38
First: 16.06.2026 13:18
Last: 16.06.2026 13:18
Sources 1
About this happening:
A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
Major U.S. services company hit by ransomware attack linked to DragonForce
IncidentAbout this happening: A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
Sentry agentjacking analysis shows malicious error events can trigger AI coding agents
Technical Analysis
H score38
First: 11.06.2026 12:15
Last: 11.06.2026 12:15
Sources 1
About this happening:
Researchers described Agentjacking as a new attack against AI coding agents that abuses Sentry DSNs and MCP to inject fake error data, causing agents like Claude...
Sentry agentjacking analysis shows malicious error events can trigger AI coding agents
Technical AnalysisAbout this happening: Researchers described Agentjacking as a new attack against AI coding agents that abuses Sentry DSNs and MCP to inject fake error data, causing agents like Claude...
Timeline
-
10.08.2026 13:45 1 articles · 3h ago
Ghostjacking attack chain abuses AI agents' trusted access to bypass firewalls
Initial DisclosureA fake bug report was shown to be enough to trick an AI coding assistant into acting on attacker-supplied input. The initial proof of concept already reached code execution on a developer machine and set up a path toward traffic rerouting and persistence.
Show sources
- “Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Controls — www.infosecurity-magazine.com — 10.08.2026 13:45
-
10.08.2026 13:45 2 articles · 3h ago
Ghostjacking demo hijacks Claude Code on Cloudflare’s recommended setup
Technical Analysis UpdateTenet Security researchers demonstrated Ghostjacking at DEFCON 2026 in Las Vegas on August 9, showing that a single fake bug report could hijack AI coding assistants, reroute an organization’s email and web traffic around its firewall, and leave backdoors in agent configuration, memory and tools for persistent access. The team said the technique succeeded nine out of 10 times against the Claude Code AI agent on Cloudflare’s recommended setup and also used Sentry’s Seer to vouch for a malicious fix.
Show sources
- “Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Controls — www.infosecurity-magazine.com — 10.08.2026 13:45
- ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad — www.securityweek.com — 10.08.2026 15:59