Tenet shows Ghostjacking attacks can poison Cloudflare, Datadog, and Sentry logs to make AI agents change DNS, run code, and steal credentials

Researchers showed that attackers can hide malicious instructions inside trusted security logs and alerts so AI agents carry out harmful actions for them. Tenet calls the technique 'Ghostjacking' and demonstrated it against Cloudflare logs, Datadog alerts, and Sentry workflows, including changing Cloudflare DNS settings, making Claude Code run commands and exfiltrate environment and cloud secrets, and using Sentry Seer to pass a malicious fix to a coding agent. Tenet also says Anthropic silently patched a Claude Desktop data-exfiltration flaw without a CVE.
Why it matters: Organizations experimenting with AI agents in security and operations could be tricked into taking damaging actions based on attacker-planted text in tools they already trust. Teams using Cloudflare, Datadog, Sentry, and Claude-based agents should review what data agents can read and what actions they can take, and add approval boundaries before agents can change settings or access secrets.

Sources

‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad
Ionut Arghire 2026.08.10 100% relevant
This article appears to be the first concrete report establishing the Ghostjacking attack pattern against named products, with specific demonstrations on Cloudflare, Datadog, and Sentry plus a separately patched Anthropic flaw.
← Back to all stories