“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Controls
ID: 0087fd26-1b30-5ab4-8ae8-d0fa92db9586
STIX ID: report--0087fd26-1b30-5ab4-8ae8-d0fa92db9586
Feed Name: Infosecurity Magazine (News)
Tenet Security presented research at DEFCON 2026 on 'Ghostjacking', a technique that leverages an organization’s own AI agents and trusted security telemetry (e.g., Cloudflare logs, Datadog alerts, Sentry reports) to execute attacker-supplied code, alter DNS and reroute email/web traffic, and implant persistent backdoors; the team demonstrated reliable proofs-of-concept across common developer platforms and recommended defensive controls such as denying outbound access by default and requiring human approval for agent actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
