Tenet Security researchers discovered a new attack called Ghostjacking that allows hackers to manipulate AI agents by hiding malicious instructions in error logs. Presented at DEF CON 34, this technique achieves approximately 90% success rate against Claude Code configurations. The attack exploits the fact that AI agents trust all ingested data by default, causing them to propose DNS changes that redirect web traffic to attacker-controlled domains. Cloudflare, Datadog, and Sentry were identified as potential vectors, with thousands of exposed tokens and keys found. At least 48 organizations, including six Fortune 500 companies, have vulnerable MCP configurations. Tenet Security released an open-source mitigation tool called agent-jackstop to address the risks.
Source: Read the original article

