All incidents

Ghostjacking attack hijacks AI agents via poisoned logs

incidentopenAug 10, 2026 — Aug 10, 2026
Ghostjacking Attack Hijacks AI Agents via Trusted Logs and Alerts

TENET Security researchers have disclosed a new attack dubbed Ghostjacking that subverts AI agents by poisoning trusted logs and alerts according to their blog. The technique impacts organisations that rely on Cloudflare, Datadog or Sentry for monitoring and incident response, including many Fortune 500 firms. By injecting malicious instructions into data the AI treats as trustworthy, attackers can prompt the agents to change DNS settings or siphon sensitive information.

The flaw does not carry a CVE identifier because it stems from a design oversight rather than a traditional software bug. AI agents ingest log entries and alert payloads without validating their origin, allowing external input to be interpreted as executable commands. This implicit trust creates a high‑severity logic weakness that can be triggered whenever the AI processes telemetry from the three platforms.

In practice an attacker first gains the ability to write to a log stream, for example through a compromised service account or a misconfigured forwarding rule. They then craft a log entry that contains a command such as “update DNS record to attacker‑controlled server”. When the AI agent reads the entry it trusts the content and executes the instruction, leading to traffic rerouting or data exfiltration.

Tenet observed activity linked to Ghostjacking between 10 August 2026 at 10:51 UTC and 13:31 UTC, although no threat actor has been publicly identified. The campaign shows that any system where AI consumes telemetry without sandboxing is vulnerable to this trust‑exploitation method. According to an Infosecurity Magazine piece half of Fortune 500 firms are estimated to be exposed.

As organisations delegate more infrastructure tasks to AI the boundary between data and command becomes increasingly blurred, raising the risk of silent persistence and lateral movement. Because the technique does not rely on a conventional software flaw it evades detection by signature‑based tools and traditional vulnerability scanners.

Defenders should enforce strict validation and sanitisation of any log or alert data before it reaches AI pipelines. They should limit write access to telemetry streams to trusted entities only and require human approval for high‑impact actions such as DNS changes. Additionally, segmenting AI agents from production networks and reviewing automation playbooks for implicit trust assumptions can reduce the chance of a successful Ghostjacking attempt.

Intelligence briefing updated Aug 10, 2026

Root sourcetenetsecurity.ai
Timeline Coverage

Swipe to explore timeline