Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Agentjacking Attack Exploits AI Coding Agents

Agentjacking Attack Exploits AI Coding Agents

Posted on June 13, 2026 By CWS

Cybersecurity experts have uncovered a novel type of cyber attack known as Agentjacking, which targets artificial intelligence (AI) coding agents to run unauthorized code on developers’ systems. This attack was identified by Tenet Security and leverages manipulated error reports generated through Sentry, an open-source error-tracking tool.

Understanding the Agentjacking Mechanism

The attack exploits a crucial flaw in the interaction between Sentry’s event ingestion system, which allows arbitrary data submissions, and the Sentry MCP server, which shares these inputs with AI agents as reliable data. Security researchers Ron Bobrov, Barak Sternberg, and Nevo Poran explained that this manipulation leads AI coding agents, such as Claude Code and Cursor, to execute malicious code.

By embedding crafted inputs in Sentry error events, attackers can trick these AI agents into considering the fake data as valid diagnostic instructions, leading to unauthorized code execution. This method can compromise sensitive information, including Git credentials and private repository URLs, without traditional phishing or server attacks.

Details of the Attack Chain

The attack initiates when an attacker discovers a target’s Sentry Data Source Name (DSN), a publicly accessible credential. The attacker then sends a malicious error event to Sentry’s ingestion endpoint, incorporating “carefully formatted markdown” to mimic legitimate system messages. When a developer instructs their AI coding agent to resolve Sentry issues, the malicious event is processed as a genuine resolution, executing harmful code with the developer’s access rights.

This attack is particularly insidious because it operates without the attacker ever compromising the victim’s infrastructure directly. The AI coding agent, trusted by developers for problem-solving, becomes a vector for executing the attacker’s commands.

Wide-Ranging Impact and Response

Agentjacking is significant due to its reliance on the trusted AI agent and Sentry DSN for propagation. Tenet Security’s research indicates that at least 2,388 organizations are vulnerable to this type of attack, with an 85% success rate in controlled tests involving popular AI coding tools.

Sentry has acknowledged the vulnerability but has chosen not to implement a direct fix, labeling it “technically not defensible.” Instead, they have activated a global content filter to block specific malicious payloads. Despite these measures, the attack remains a concern as it bypasses many traditional security defenses like EDR, WAF, and firewalls.

Tenet Security emphasizes the growing risk as enterprises rapidly deploy AI coding agents, highlighting that these tools have become a new attack surface. The attack illustrates how data published by organizations can be weaponized, underscoring the need for heightened vigilance and improved security measures in AI systems.

The Hacker News Tags:Agentjacking, AI assistants, AI security, AI vulnerability, coding agents, cyber attack, Cybersecurity, data breach, DSN exposure, error injection, malicious code, Model Context Protocol, Sentry, Sentry vulnerability, Tenet Security

Post navigation

Previous Post: OnyxC2 Malware Exploits 210 Apps to Steal Credentials
Next Post: Ivanti Sentry Vulnerability Exploitation Detected

Related Posts

AI Security Concerns in Amazon Bedrock and Other Platforms AI Security Concerns in Amazon Bedrock and Other Platforms The Hacker News
Fake Security Plugin on WordPress Enables Remote Admin Access for Attackers Fake Security Plugin on WordPress Enables Remote Admin Access for Attackers The Hacker News
New Atomic macOS Stealer Campaign Exploits ClickFix to Target Apple Users New Atomic macOS Stealer Campaign Exploits ClickFix to Target Apple Users The Hacker News
That Network Traffic Looks Legit, But it Could be Hiding a Serious Threat That Network Traffic Looks Legit, But it Could be Hiding a Serious Threat The Hacker News
FROST Attack Exploits SSD Timing to Track Website Visits FROST Attack Exploits SSD Timing to Track Website Visits The Hacker News
CastleLoader Malware Infects 469 Devices Using Fake GitHub Repos and ClickFix Phishing CastleLoader Malware Infects 469 Devices Using Fake GitHub Repos and ClickFix Phishing The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OceanLotus Targets Vietnamese Firms with SPECTRALVIPER
  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution
  • Worm Code Breach and AI Risks Highlight Cyber Threats
  • Cybersecurity Stars Awards 2026: 95 Winners Revealed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OceanLotus Targets Vietnamese Firms with SPECTRALVIPER
  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution
  • Worm Code Breach and AI Risks Highlight Cyber Threats
  • Cybersecurity Stars Awards 2026: 95 Winners Revealed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark