'GhostJacking' Exposes Identity Governance Gaps in AI Agents
ID: bf71be6e-4f11-5810-b830-360b233f6014
STIX ID: report--bf71be6e-4f11-5810-b830-360b233f6014
Feed Name: Dark Reading
Tenet Security demonstrated at DEF CON 34 that attackers can poison trusted telemetry (logs, alerts, diagnostics) to trick AI agents into executing attacker-supplied actions — from stealing cloud credentials to modifying DNS and taking over infrastructure — across platforms such as Cloudflare, Datadog, and Sentry; the issue stems from agents that both read external data and act on it, and Tenet recommends least-privilege scopes, short-lived credentials, human approval for execution, and immutable prompt/output logging as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
