logo

'GhostJacking' Exposes Identity Governance Gaps in AI Agents

ID: bf71be6e-4f11-5810-b830-360b233f6014

STIX ID: report--bf71be6e-4f11-5810-b830-360b233f6014

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-08-10

Date Updated: 2026-08-11

Author: Jai Vijayan

...
...

Tenet Security demonstrated at DEF CON 34 that attackers can poison trusted telemetry (logs, alerts, diagnostics) to trick AI agents into executing attacker-supplied actions — from stealing cloud credentials to modifying DNS and taking over infrastructure — across platforms such as Cloudflare, Datadog, and Sentry; the issue stems from agents that both read external data and act on it, and Tenet recommends least-privilege scopes, short-lived credentials, human approval for execution, and immutable prompt/output logging as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.