Researchers showed that attackers can hide malicious instructions inside trusted security logs and alerts so AI agents carry out harmful actions for them. Tenet calls the technique 'Ghostjacking' and demonstrated it against Cloudflare logs, Datadog alerts, and Sentry workflows, including changing Cloudflare DNS settings, making Claude Code run commands and exfiltrate environment and cloud secrets, and using Sentry Seer to pass a malicious fix to a coding agent. Tenet also says Anthropic silently patched a Claude Desktop data-exfiltration flaw without a CVE.
Why it matters: Organizations experimenting with AI agents in security and operations could be tricked into taking damaging actions based on attacker-planted text in tools they already trust. Teams using Cloudflare, Datadog, Sentry, and Claude-based agents should review what data agents can read and what actions they can take, and add approval boundaries before agents can change settings or access secrets.
Ionut Arghire
2026.08.10
100% relevant
This article appears to be the first concrete report establishing the Ghostjacking attack pattern against named products, with specific demonstrations on Cloudflare, Datadog, and Sentry plus a separately patched Anthropic flaw.
← Back to all stories