Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Are AI tutoring tools safe for your kids?

August 10, 2026

“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Co

August 10, 2026

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

August 10, 2026
Facebook X (Twitter) Instagram
Monday, August 10
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Co
News

“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Co

Team-CWDBy Team-CWDAugust 10, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Half of Fortune 500 companies are vulnerable to attacks enabled by their own AI agents bypassing firewall defenses, according to new research by Tenet Security.

The technique, dubbed ‘Ghostjacking’, involves the use of an organization’s own AI agents to reroute the company’s email and web traffic, opening a hidden path around its firewall.

Tenet Security researchers demonstrated how a single fake bug report could hijack AI coding assistants and run an attacker’s code on a developer’s machine.

The attack cannot be flagged to defenders as the agents use access they have already been granted, and while the firewall doesn’t go down it becomes irrelevant.

Attackers can also exploit the flaw to leave backdoors in the agent’s configuration, memory and tools, providing them with persistent access into the victim organization for the purposes such as data and credential theft.

The researchers even demonstrated one case in which they could get one AI agent to build an attack that another AI would accept, which was described as a “self-exploit” technique.

This attack chain succeeds across software platforms commonly used by developers, including Cloudflare, Datadog and Sentry.

The findings were presented on the main stage at DEFCON 2026 in Las Vegas on August 9. The Tenet team demonstrated that the Ghostjacking technique succeeded nine out of 10 times against the Claude Code AI agent, on Cloudflare’s own recommended set up.

Among the organizations known to run the exposed Cloudflare set up are a trillion-dollar global technology company, a global payments provider and a leading AI research lab.

The study noted that Cloudflare is run in 42% of Fortune 500 firms, and carries a fifth of all internet traffic, while Datadog runs in 48% of these companies and Sentry is used by four million developers.

The findings further highlight the risks by organizations increasingly entrusting AI agents with full access to their code and infrastructure, with the agents unable to distinguish between a real instruction from a trap hidden in the data it reads.

How One Fake Report Tricks AI Agents

Tenet said that Ghostjacking is the next evolution of the ‘Agentjacking’ attack class, which involves tricking AI coding agents into executing arbitrary code on developer machines.

Ghostjacking sees the company’s own security controls essentially act as the delivery system for a full domain takeover.

With the Cloudflare firewall, when it prevents a bad request by a malicious actor, it records it word-for-word in the logs. This means an attacker’s planted log will be read by the AI as if it were a real finding when asked to review the blocked events by an analyst.

The same AI will rewrite the company’s DNS, point the domain at the attacker and report the issue as resolved. This can allow an attacker to quietly reroute website traffic and emails.

“It is Cloudflare’s managed security rule that blocks the request, and that block is what carries the attack in,” Tenet said.

The Datadog platform was similarly exposed to Ghostjacking because its key, meant only for a website’s front end, is routinely left public. The Tenet researchers discovered more than 2700 of these keys.

The key can be used to plant a fake “urgent diagnostic alert”, which is read by the AI agent when asked by an engineer to check for errors.

With Sentry, the researchers even used the platform’s own AI, Seer, to “vouch” for them to the next agent. This is because Seer reads the fake report and attacker’s fake fix as its own conclusion, which is trusted by the coding agent, thereby running the malicious code.

“Sentry, Cloudflare, and Datadog are not three separate flaws. They are the same shape. An AI reads outside data it trusts, and the same AI can also act on it. Wherever those two things meet, the door is open. The same pattern shows up far beyond these three, in setups like Splunk with a build system, or Datadog with Kubernetes,” the researchers noted.

The findings were reported by Tenet to Sentry, Datadog and Cloudflare in June.

Tenet recommended that companies take the following actions to reduce their exposure to Ghostjacking:

  • Deny outbound network access by default. This alone stops the attacker’s download and the data leak
  • Require a human to approve any command the agent wants to run
  • Never let data an agent reads become an instruction it runs
  • Assume any reachable token is at risk, and review every tool the agent connects to



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleKali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
Next Article Are AI tutoring tools safe for your kids?
Team-CWD
  • Website

Related Posts

News

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

August 10, 2026
News

Go-Based macOS Malware Steals Crypto and Secrets

August 10, 2026
News

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

August 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What to consider before asking an AI chatbot for health advice

May 27, 2026

AI-powered financial scams swamp social media

September 11, 2025

How it preys on personal data – and how to stay safe

October 23, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.