www.darkreading.com 8/10/2026, 10:51:15 PM · external

'GhostJacking' Exposes Identity Governance Gaps in AI Agents

'GhostJacking' Exposes Identity Governance Gaps in AI Agents
Developing story incident 3 articles tracked
Ghostjacking attack hijacks AI agents via poisoned logs
CyberSIXT Evidence Panel
Primary Source tenetsecurity.ai

NEW research from Tenet Security highlights the vulnerabilities in AI agents, exposing how attackers can exploit security alerts to hijack these systems, a technique termed 'GhostJacking.' At DEF CON 34, they showcased methods for poisoning trusted telemetry data, tricking AI agents into executing malicious tasks such as code execution and credential theft.

The attackers demonstrated the ease of manipulating AI agents using content they normally trust, illustrating systemic weaknesses rather than specific bugs in existing identity governance practices. Key recommendations for organizations include enforcing the principle of least privilege for AI agents, ensuring human oversight on their actions, and maintaining comprehensive logging to trace agent behavior.

View Primary Source Via www.darkreading.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline