Tenet Security researchers demonstrated at DEFCON 34 a new attack called Ghostjacking, which hijacks AI agents by poisoning their log files and alerts. The attack achieved a 90% success rate against Anthropic’s Claude Code under Cloudflare’s default configuration, with Cloudflare handling approximately 20% of internet traffic. Over 15,000 organizations could be exposed through vulnerable Cloudflare configurations, and more than 2,700 Datadog API keys were found publicly exposed. This technique enables a complete attack chain including initial access, privilege escalation, data exfiltration, and persistence, without triggering standard security tools. The fundamental issue stems from how language models process all input as potential instructions, a vulnerability that transcends any specific vendor.
Source: Read the original article

