Overview
- Tenet Security publicly demonstrated the technique on Sunday at DEF CON, showing AI agents can read attacker-crafted logs or alerts and then perform actions that bypass firewall controls.
- The researchers built end-to-end exploits across Cloudflare, Datadog and Sentry that allowed domain takeover, code execution, cloud credential theft and persistent backdoors.
- In lab tests Tenet said the attack worked nine times out of ten against Claude Code on a Cloudflare-recommended setup and they found more than 2,700 exposed Datadog front-end keys that can deliver fake urgent alerts.
- Anthropic patched a Claude Desktop flaw disclosed by Tenet and the company published operational mitigations that include denying outbound agent network access by default and requiring human approval for agent-run commands.
- The attack is a workflow design problem rather than a single bug, so many large organizations that let agents read logs and act on tools remain at risk and should review token exposure, logging practices and agent permissions.