Tenet Researchers Detail 'Ghostjacking' AI Agent Attack
TL;DR. Tenet security researchers uncovered a 'Ghostjacking' attack where poisoned logs turn AI agents rogue, exploiting trusted platforms like Cloudflare and Datadog. - Attackers inject malicious instructions into system logs or alerts that AI agents then read and execute. - This method bypassed Cloudflare’s security configuration and allowed domain hijacking and credential theft. - The vulnerability affects major enterprise platforms, raising concerns about AI agent safety and trust.
- Tenet researchers demonstrated 'Ghostjacking,' a new AI hijacking attack.
- The attack uses poisoned logs or alerts to deliver malicious instructions to AI agents.
- Cloudflare, Datadog, and Sentry platforms were identified as vulnerable to this attack vector.
Sources
- ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad — securityweek.com
- theregister.com — theregister.com
- engadget.com — engadget.com
- techcrunch.com — techcrunch.com