In a groundbreaking revelation at DEF CON, Tenet security researchers demonstrated a new AI hijacking technique called Ghostjacking. This attack manipulates AI agents using trusted tools to inject malicious commands, posing a significant threat to cybersecurity.
Exploring the Ghostjacking Method
The Israeli startup Tenet, which came into the spotlight in June, showcased how attackers can corrupt AI agents by embedding harmful instructions within logs or alerts. This method, known as Ghostjacking, expands on their earlier concept of ‘Agentjacking,’ where data poisoning alters AI behavior.
Ghostjacking exploits vulnerabilities in widely trusted platforms such as Cloudflare, Datadog, and Sentry. Cloudflare manages 20% of internet traffic, while Datadog and Sentry are integral to many Fortune 500 companies and millions of developers, respectively.
Impact on Cloudflare, Datadog, and Sentry
The attack strategy involves leveraging Cloudflare’s security settings, which inadvertently allow malicious requests to be logged verbatim. When an AI analyzes these logs, it may execute the embedded malicious instructions, redirecting DNS settings to attacker-controlled domains.
Datadog’s vulnerability stems from exposed API keys, which attackers can use to send fake alerts. These alerts trick AI agents into executing unauthorized commands, compromising sensitive data and cloud credentials.
Sentry’s AI agent, known as Seer, can be deceived into adopting bogus fixes, which are then executed by trusted systems. This chain reaction underscores the potential for widespread disruption.
Broader Implications and Preventative Measures
Tenet’s research highlights a broader security concern: AI agents reading and acting on external data without proper safeguards. This pattern is not limited to Cloudflare, Datadog, and Sentry, but is also seen in other systems like Splunk and Kubernetes.
In a controlled test, Tenet demonstrated how AI agents can be manipulated into executing self-targeted attacks, revealing critical insights for strengthening AI security. They also identified and reported a vulnerability in Claude Desktop, which was promptly addressed by Anthropic.
As AI technology becomes more integrated into organizational infrastructures, understanding and mitigating risks like Ghostjacking is crucial. Enhanced security protocols and vigilant monitoring are essential to protect against such sophisticated cyber threats.
