Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ghostjacking Threatens AI Security Through Trusted Tools

Ghostjacking Threatens AI Security Through Trusted Tools

Posted on August 10, 2026 By CWS

In a groundbreaking revelation at DEF CON, Tenet security researchers demonstrated a new AI hijacking technique called Ghostjacking. This attack manipulates AI agents using trusted tools to inject malicious commands, posing a significant threat to cybersecurity.

Exploring the Ghostjacking Method

The Israeli startup Tenet, which came into the spotlight in June, showcased how attackers can corrupt AI agents by embedding harmful instructions within logs or alerts. This method, known as Ghostjacking, expands on their earlier concept of ‘Agentjacking,’ where data poisoning alters AI behavior.

Ghostjacking exploits vulnerabilities in widely trusted platforms such as Cloudflare, Datadog, and Sentry. Cloudflare manages 20% of internet traffic, while Datadog and Sentry are integral to many Fortune 500 companies and millions of developers, respectively.

Impact on Cloudflare, Datadog, and Sentry

The attack strategy involves leveraging Cloudflare’s security settings, which inadvertently allow malicious requests to be logged verbatim. When an AI analyzes these logs, it may execute the embedded malicious instructions, redirecting DNS settings to attacker-controlled domains.

Datadog’s vulnerability stems from exposed API keys, which attackers can use to send fake alerts. These alerts trick AI agents into executing unauthorized commands, compromising sensitive data and cloud credentials.

Sentry’s AI agent, known as Seer, can be deceived into adopting bogus fixes, which are then executed by trusted systems. This chain reaction underscores the potential for widespread disruption.

Broader Implications and Preventative Measures

Tenet’s research highlights a broader security concern: AI agents reading and acting on external data without proper safeguards. This pattern is not limited to Cloudflare, Datadog, and Sentry, but is also seen in other systems like Splunk and Kubernetes.

In a controlled test, Tenet demonstrated how AI agents can be manipulated into executing self-targeted attacks, revealing critical insights for strengthening AI security. They also identified and reported a vulnerability in Claude Desktop, which was promptly addressed by Anthropic.

As AI technology becomes more integrated into organizational infrastructures, understanding and mitigating risks like Ghostjacking is crucial. Enhanced security protocols and vigilant monitoring are essential to protect against such sophisticated cyber threats.

Security Week News Tags:Agentjacking, AI attack, AI security, Anthropic, Claude Code, Cloudflare, Cybersecurity, Datadog, Ghostjacking, Sentry

Post navigation

Previous Post: Passkey Flaws Exposed: New Attacks on Authentication Methods
Next Post: Ransomware Tactics: Disabling Security Before Encryption

Related Posts

CrowdStrike to Acquire Onum to Fuel Falcon Next-Gen SIEM With Real-Time Telemetry CrowdStrike to Acquire Onum to Fuel Falcon Next-Gen SIEM With Real-Time Telemetry Security Week News
Microsoft and Steam Take Action as Unity Vulnerability Puts Games at Risk Microsoft and Steam Take Action as Unity Vulnerability Puts Games at Risk Security Week News
Reach Security Raises  Million for Exposure Management Solution Reach Security Raises $10 Million for Exposure Management Solution Security Week News
Vulnerability Exposes Data Leaks in Moltbook AI Network Vulnerability Exposes Data Leaks in Moltbook AI Network Security Week News
Kosovar Administrator of Cybercrime Marketplace Extradited to US Kosovar Administrator of Cybercrime Marketplace Extradited to US Security Week News
Fighting the Cyber Forever War: Born Defense Blends Investment Strategy with Just War Principles Fighting the Cyber Forever War: Born Defense Blends Investment Strategy with Just War Principles Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CEVA Logistics Breach Exposes Steam Hardware Buyers
  • Stealthium Enhances Security for AI Accelerators and Neo-Clouds
  • North Korean Hackers Utilize AI for Enhanced Phishing Tactics
  • Ransomware Tactics: Disabling Security Before Encryption
  • Ghostjacking Threatens AI Security Through Trusted Tools

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CEVA Logistics Breach Exposes Steam Hardware Buyers
  • Stealthium Enhances Security for AI Accelerators and Neo-Clouds
  • North Korean Hackers Utilize AI for Enhanced Phishing Tactics
  • Ransomware Tactics: Disabling Security Before Encryption
  • Ghostjacking Threatens AI Security Through Trusted Tools

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark