Ghostjacking attack uses poisoned logs to compromise AI agents

1 hour ago 2



Security researchers have found a way to turn the tools companies trust most against them. The attack, called Ghostjacking, manipulates AI agents into executing harmful actions by poisoning the very logs and alerts those agents are designed to monitor. Tenet Security unveiled the technique at DEFCON 34 on August 9, demonstrating how attackers can inject malicious instructions into data streams from platforms like Cloudflare, Datadog, and Sentry. The result: AI agents that obediently make DNS changes, execute code, and steal credentials, all while thinking they’re doing their job. How Ghostjacking works Tenet’s research showed a 90% success rate against Claude Code when operating under Cloudflare’s default configuration settings. Cloudflare handles roughly 20% of internet traffic, and approximately 42% of Fortune 500 companies rely on it. Datadog, also affected, is used by about 48% of Fortune 500 companies. The attack builds on Tenet’s earlier research into what they called Agentjacking, but extends the concept dramatically. Where the previous work demonstrated the theoretical risk, Ghostjacking shows a complete agentic kill chain: initial access, privilege escalation, data exfiltr...

Read Entire Article