‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad
An AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word. The post ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad appeared first on SecurityWeek .
AI Analysis
Technical Summary
Tenet security researchers demonstrated 'Ghostjacking,' an AI hijacking attack where attackers plant malicious instructions in logs or alerts that AI agents trust and execute. The attack leverages three widely used platforms: Cloudflare, Datadog, and Sentry. For Cloudflare, blocked requests are logged verbatim, allowing attackers to inject commands that AI agents later execute, such as altering DNS settings to attacker-controlled domains. In Datadog, exposed frontend keys enable attackers to plant fake urgent alerts that AI agents interpret and execute, leading to code execution and credential exfiltration. In Sentry, attackers craft reports that AI agents adopt as fixes, which then execute malicious code downstream. The attack exploits the fundamental issue of AI agents reading and acting on untrusted external data sources. Additionally, a vulnerability in Claude Desktop was discovered and fixed by Anthropic without a CVE. The attack pattern extends beyond these platforms to other setups where AI agents read and act on trusted data, such as Splunk with build systems or Datadog with Kubernetes.
Potential Impact
The attack enables adversaries to manipulate AI agents into executing malicious commands by injecting instructions into logs or alerts that the AI trusts and acts upon. This can lead to domain hijacking, unauthorized code execution, credential theft, and insider-like behavior by compromised AI agents. The attack bypasses traditional security controls by leveraging trusted data sources and AI automation, potentially compromising cloud infrastructure and developer environments. The vulnerability in Claude Desktop could allow data exfiltration to remote servers. The widespread use of the targeted platforms increases the potential impact across many organizations.
Mitigation Recommendations
No official vendor advisories or patches are referenced for this attack pattern, except that Anthropic fixed the Claude Desktop vulnerability without issuing a CVE. Organizations should review and harden configurations that log blocked requests verbatim, restrict exposure of API keys (such as Datadog frontend keys), and carefully validate or sanitize data that AI agents consume and act upon. Limiting AI agents' ability to execute commands based solely on untrusted external data is critical. Monitoring for unusual AI agent behavior and applying defense-in-depth controls around AI automation workflows are recommended. Patch status is not yet confirmed for the broader attack vectors—check vendor advisories for Cloudflare, Datadog, and Sentry for updates.
‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad
Description
An AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word. The post ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad appeared first on SecurityWeek .
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Tenet security researchers demonstrated 'Ghostjacking,' an AI hijacking attack where attackers plant malicious instructions in logs or alerts that AI agents trust and execute. The attack leverages three widely used platforms: Cloudflare, Datadog, and Sentry. For Cloudflare, blocked requests are logged verbatim, allowing attackers to inject commands that AI agents later execute, such as altering DNS settings to attacker-controlled domains. In Datadog, exposed frontend keys enable attackers to plant fake urgent alerts that AI agents interpret and execute, leading to code execution and credential exfiltration. In Sentry, attackers craft reports that AI agents adopt as fixes, which then execute malicious code downstream. The attack exploits the fundamental issue of AI agents reading and acting on untrusted external data sources. Additionally, a vulnerability in Claude Desktop was discovered and fixed by Anthropic without a CVE. The attack pattern extends beyond these platforms to other setups where AI agents read and act on trusted data, such as Splunk with build systems or Datadog with Kubernetes.
Potential Impact
The attack enables adversaries to manipulate AI agents into executing malicious commands by injecting instructions into logs or alerts that the AI trusts and acts upon. This can lead to domain hijacking, unauthorized code execution, credential theft, and insider-like behavior by compromised AI agents. The attack bypasses traditional security controls by leveraging trusted data sources and AI automation, potentially compromising cloud infrastructure and developer environments. The vulnerability in Claude Desktop could allow data exfiltration to remote servers. The widespread use of the targeted platforms increases the potential impact across many organizations.
Defensive Guidance
No official vendor advisories or patches are referenced for this attack pattern, except that Anthropic fixed the Claude Desktop vulnerability without issuing a CVE. Organizations should review and harden configurations that log blocked requests verbatim, restrict exposure of API keys (such as Datadog frontend keys), and carefully validate or sanitize data that AI agents consume and act upon. Limiting AI agents' ability to execute commands based solely on untrusted external data is critical. Monitoring for unusual AI agent behavior and applying defense-in-depth controls around AI automation workflows are recommended. Patch status is not yet confirmed for the broader attack vectors—check vendor advisories for Cloudflare, Datadog, and Sentry for updates.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/ghostjacking-attack-uses-poisoned-logs-to-turn-ai-agents-bad/","fetched":true,"fetchedAt":"2026-08-10T13:11:13.341Z","wordCount":1318}
Threat ID: 6a79cdf1bf8831d539b89869
Added to database: 08/10/2026, 13:11:13 UTC
Last enriched: 08/10/2026, 13:11:27 UTC
Last updated: 08/11/2026, 04:00:49 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.