NEW research from Tenet Security highlights the vulnerabilities in AI agents, exposing how attackers can exploit security alerts to hijack these systems, a technique termed 'GhostJacking.' At DEF CON 34, they showcased methods for poisoning trusted telemetry data, tricking AI agents into executing malicious tasks such as code execution and credential theft.
The attackers demonstrated the ease of manipulating AI agents using content they normally trust, illustrating systemic weaknesses rather than specific bugs in existing identity governance practices. Key recommendations for organizations include enforcing the principle of least privilege for AI agents, ensuring human oversight on their actions, and maintaining comprehensive logging to trace agent behavior.