< Back to all clusters
[TECHNOLOGY] · 6 sources

started · updated

Ghostjacking attack exploits AI agents via poisoned logs

Security researchers at Tenet Security have unveiled ‘Ghostjacking’, a new attack technique that manipulates AI agents by poisoning the logs and alerts they are designed to monitor. By embedding natural language commands into data streams from platforms such as Cloudflare, Datadog, and Sentry, attackers can trick AI agents into executing malicious instructions while the agents believe they are performing routine tasks.

The attack exploits an architectural vulnerability in how large language models process information, treating all input as potential instructions. In demonstrations, the technique achieved a 90% success rate against Anthropic’s Claude Code under certain configurations. Successful exploits can lead to DNS hijacking, unauthorized code execution, credential theft, and the creation of persistent backdoors.

The potential scale of exposure is significant; Tenet estimates that over 15,000 organizations could be vulnerable through specific Cloudflare configurations alone. Furthermore, the research highlights a risk of cascading failures, where a compromised agent on one platform can pass malicious instructions to agents on other platforms, creating a chain reaction across an organization’s infrastructure.

Entities

Anthropic · Cloudflare · Datadog · Sentry · Tenet Security