Tenet Security disclosed Ghostjacking, an attack technique that hides malicious instructions inside trusted operational data such as logs, alerts, and error reports, then tricks AI agents into executing those instructions with their own legitimate permissions. Presented at DEF CON, the research showed that a single fake bug report or poisoned log entry could cause coding and operations agents to alter DNS records, run commands, expose frontend keys, and exfiltrate environment secrets or cloud credentials while falsely reporting that tasks had completed successfully.
The demonstrations involved workflows tied to Cloudflare, Datadog, and Sentry, and researchers said the problem reflects a broader architectural weakness rather than isolated product flaws: the same AI system both trusts external data and is allowed to take action on it. Tenet also reported that Anthropic fixed a Claude Desktop issue that could enable remote data exfiltration, though no CVE was assigned. The findings highlight identity-governance gaps in agentic systems and have prompted calls for least-privilege access, short-lived credentials, human approval for sensitive actions, and immutable logging of agent prompts and outputs.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Tenet Security published research describing an "Agentjacking" technique in which trusted telemetry or bug-report style inputs can be poisoned to manipulate AI coding agents into executing malicious commands. Later GhostJacking reporting explicitly says this earlier report was released in June and served as the foundation for the broader attack model.
Tenet Security presented its new "GhostJacking" research at DEF CON 34, describing a broader attack pattern in which AI agents trust attacker-influenced logs, alerts, and reports and then act on them with legitimate permissions. The presentation framed Cloudflare, Datadog, and Sentry demonstrations as examples of the same underlying design issue rather than isolated bugs.
Tenet found a Claude Desktop vulnerability that could be exploited for remote data exfiltration, and Anthropic fixed it without issuing a CVE. The references do not anchor when the flaw was discovered or fixed beyond reporting that the fix had already occurred.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcedarkreading.com
Open sourcesecurityweek.com
Open sourceinfosecurity-magazine.com
Open sourcetenetsecurity.ai
Open sourcetenetsecurity.ai
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.