cognitive cybersecurity intelligence

News and Analysis

Search

New ‘Ghostjacking’ Attack Lets Hackers Hijack AI Agents to Run Their Code on Developer Machines

New ‘Ghostjacking’ Attack Lets Hackers Hijack AI Agents to Run Their Code on Developer Machines

A new AI-agent attack technique called “Ghostjacking,” can trick coding agents into running attacker-controlled commands, changing cloud settings, stealing credentials, and creating persistent backdoors.

The research was presented by Tenet Security at DEF CON 34 in Las Vegas on August 9, 2026. Tenet said the attack affects a growing class of AI-enabled workflows in which coding assistants can read information from trusted tools and then take action in development or cloud environments.

Ghostjacking is based on indirect prompt injection. Instead of sending a malicious command directly to an AI coding assistant, an attacker embeds harmful instructions in data the agent is likely to inspect. This could include a blocked web request, an error log, a monitoring alert, or a bug report.

When a developer asks an AI agent to investigate the data, the agent may interpret the attacker’s content as a legitimate instruction. If the agent has access to shell commands, cloud dashboards, DNS records, source code, or secrets, it could perform dangerous actions using permissions already granted by the organization.

Ghostjacking Attack Hijack AI Coding Agents

Tenet demonstrated the issue across Cloudflare, Datadog, and Sentry integrations. In one scenario, an attacker sent a malicious request to a website protected by Cloudflare.

The firewall correctly blocked the request and logged it. However, when an analyst asked an AI assistant to review the blocked events, the assistant processed the attacker-controlled text embedded in the log.

The Ghostjacking Attacks (source: Tenet Security)

The researchers said the compromised agent could then modify DNS settings and redirect a company’s web and email traffic. In tests against Claude Code, Tenet claimed a 90 percent success rate using Cloudflare’s recommended setup.

The firewall blocked the request, but the resulting log entry became the attack’s delivery mechanism. A similar technique was demonstrated against Datadog.

Researchers said attackers could use publicly exposed client-side keys to create fake alerts containing urgent-looking diagnostic instructions. An AI agent reviewing those alerts could be persuaded to execute commands that expose environment variables and cloud credentials.

The Sentry attack chain focused on AI-to-AI trust. Sentry’s AI assistant, Seer, could analyze a crafted issue report and produce an attacker-controlled recommendation. A separate coding agent might then trust Seer’s conclusion and execute the proposed fix without seeing the original malicious content.

Tenet also disclosed a now-patched sandbox escape in Anthropic’s Claude Desktop. According to the researchers, the flaw could have enabled data collected by an AI agent to leave a sandbox designed to restrict outbound access. Anthropic reportedly confirmed and remediated the issue before the DEF CON presentation.

The larger concern is that Ghostjacking does not require traditional exploitation such as breaking authentication or deploying malware. The AI agent performs authorized actions, making it harder for endpoint detection, web application firewalls, and identity systems to detect it as malicious.

Tenet recommends restricting AI-agent network access by default, requiring human approval before executing commands, separating untrusted data from agent instructions, and reviewing every token and external tool used in an AI workflow.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post New ‘Ghostjacking’ Attack Lets Hackers Hijack AI Agents to Run Their Code on Developer Machines appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts