Particle.news

Tenet Demonstrates ‘Ghostjacking’ That Turns Trusted AI Agents into Attack Paths

The research exposes a design gap in which AI agents ingest plain-text observability data, creating actionable instructions attackers can plant.

Overview

  • Tenet Security publicly demonstrated the technique on Sunday at DEF CON, showing AI agents can read attacker-crafted logs or alerts and then perform actions that bypass firewall controls.
  • The researchers built end-to-end exploits across Cloudflare, Datadog and Sentry that allowed domain takeover, code execution, cloud credential theft and persistent backdoors.
  • In lab tests Tenet said the attack worked nine times out of ten against Claude Code on a Cloudflare-recommended setup and they found more than 2,700 exposed Datadog front-end keys that can deliver fake urgent alerts.
  • Anthropic patched a Claude Desktop flaw disclosed by Tenet and the company published operational mitigations that include denying outbound agent network access by default and requiring human approval for agent-run commands.
  • The attack is a workflow design problem rather than a single bug, so many large organizations that let agents read logs and act on tools remain at risk and should review token exposure, logging practices and agent permissions.