Ghostjacking: Turning Logs and Alerts into Commands to Take Over AI Agents
1. Basic Information
Article Title: GhostJacking Attacks: Half of the Fortune 500 Run These Tools
Publisher: Tenet Security Threat Labs
Publication Date: August 9, 2026
Ghostjacking: Turning Logs and Alerts into Commands to Take Over AI Agents 1....
Attackers hide commands in monitoring logs and alerts; AI agents with write access execute them as tool calls to hijack DNS, steal cloud secrets, and run code. Tech governance must isolate read from write permissions, validate untrusted data, require approvals—sandbox containment alone is insufficient.
Ghostjacking: Turning Logs and Alerts into Commands to Take Over AI Agents
1. Basic Information
Article Title: GhostJacking Attacks: Half of the Fortune 500 Run These Tools
Publisher: Tenet Security Threat Labs
Publication Date: August 9, 2026

Tenet Security's Ghostjacking attack hijacks AI agents through poisoned logs from Cloudflare and Datadog, achieving a 90% success…

In a Ghostjacking attack, an AI agent executes instructions planted in the log that records a blocked request word for word.

New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents.

"Agentjacking" is the latest demonstration of how easily attackers can exploit an AI agent's inability to differentiate between…

Agentjacking exploits public Sentry DSNs to hijack Claude Code, Cursor, and Codex into running malicious code. 2,388 orgs at…

Tenet Security's Agentjacking exploit hijacks AI coding agents like Claude Code, Cursor, and Codex with an 85% success rate,…

"GhostJacking" Exposes Identity Governance Gaps in AI Agents