New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents.
August 10, 2026
New research once again demonstrates the need strong identity governance and operational guardrails around AI agents to protect against hijacking attacks that leverage their legitimate access and privileges against their very users.
At a DEF CON 34 session this week, Tenet Security demonstrated how attackers can poison content in trusted systems such as security alerts, logs, and error reports, tricking agents into actions ranging from executing code and stealing credentials to infrastructure takeover.
Tenet Security's new "GhostJacking" research builds on an earlier report in June that demonstrated how attackers could poison trusted telemetry to trick AI coding agents into executing malicious commands. The new research expands on the company's original "Agentjacking" technique with a broader attack model involving multiple trusted data sources and a wider range of potentially damaging actions.












