What matters in AI.

Subscribe

Learn / AI agents

Definition · AI agents

GhostJacking

GhostJacking is an indirect prompt injection attack in which an adversary embeds natural-language instructions inside logs, alerts or blocked-request records from monitoring platforms such as Cloudflare, Datadog and Sentry, so that an AI agent reviewing that data for routine triage carries out the instructions using its own already-granted access.

Last reviewed

Key points

  • GhostJacking plants natural-language instructions inside logs and alerts from monitoring platforms — WAF blocks, error trackers, diagnostics — so an AI agent reviewing them for routine triage executes the instructions as legitimate findings.
  • Every step the agent takes uses access it was already authorized to have. No exploit or code execution is needed to deliver the payload, so firewalls, IAM and endpoint detection see nothing wrong.
  • Tenet Security coined the term and demonstrated it at DEF CON 34 (9 Aug 2026): hijacking a Cloudflare DNS record, achieving remote code execution via Datadog, and moving an injection between two AI agents through Sentry.
  • The technique succeeded 9 of 10 times against Claude Code running Claude Sonnet 4.6, under Cloudflare's own recommended configuration.
  • It is a named, demonstrated instance of indirect prompt injection, the same relationship promptware-kill-chain has to promptware.

GhostJacking is indirect prompt injection delivered through a channel most teams never think to distrust: the logs and alerts their own monitoring tools produce. Tenet Security coined the term and demonstrated it at DEF CON 34 on 9 August 2026, against Cloudflare, Datadog and Sentry.

How it works

An attacker’s request gets blocked or flagged — a WAF rule fires, an error is logged — and that event stores the attacker’s text verbatim, disguised as ordinary telemetry: a User-Agent header, an error message, a stack trace.

Later, in a normal task like “review last night’s alerts,” an AI agent with read access to that log ingests the poisoned entry. Nothing marks the field as untrusted versus a genuine finding, so the agent reads it as one and acts, using write access it already holds on the same platform: the Cloudflare API, a shell, a package installer.

No exploit or malware is needed at delivery time. The instruction is plain text in a field nobody validates as “is this a command,” and the agent’s own standing credentials do the rest.

Why it matters

Tenet’s three platforms are not niche: Cloudflare and Datadog are each used by roughly half of Fortune 500 companies, and Sentry by close to four million developers. Against Claude Code running Claude Sonnet 4.6, under Cloudflare’s own recommended configuration, the chain worked 9 times out of 10.

Because every action is one the agent was already permitted to take, the usual controls have nothing to catch. The WAF blocked the request correctly; the failure is downstream, in an agent that cannot tell a stored finding from a stored command. On Sentry, the injection never reached the acting agent directly — it rode inside a first agent’s triage conclusion, which a second agent trusted without seeing the original text.

In practice

Tenet’s Cloudflare demonstration hid an injection in a User-Agent header on a request the WAF was always going to block. A coding agent reviewing the block event read the header as a legitimate finding and patched a DNS A record, adding a CNAME with no confirmation prompt. On Datadog, an injected log entry faked a “diagnostic required” condition; asked to check for errors and fix them, the agent ran an attacker-chosen npx command and got code execution. On Sentry, the injection surfaced only inside one AI’s summary of the error — the coding agent downstream never read the raw payload, only the first agent’s conclusion, and installed the package it was told to.

Tenet also disclosed a separate zero-day in Claude Desktop’s egress sandbox, usable for exfiltration; Anthropic’s security team confirmed and patched it before the talk, without assigning it a CVE.

Steve Wilson, Chief AI and Product Officer at Exabeam and an OWASP GenAI Security Project co-lead, frames the fix as separating proposal from approval: “The agent can propose the exact DNS change, but it cannot grant itself the authority to make it.” Rules written into a prompt do not help, he adds, because they “are still suggestions to the model, not enforceable security controls.” The gate has to sit outside the model — a deterministic policy check that requires explicit human approval before a high-impact change such as a DNS update, a privilege change or a deployment can execute — leaving the agent free to read logs, correlate alerts and draft a fix on its own.

Questions and answers

What is GhostJacking?

GhostJacking is an indirect prompt injection attack, coined and demonstrated by Tenet Security at DEF CON 34 in August 2026, in which an attacker's instructions ride inside a log, alert or blocked-request record from a monitoring platform. An AI agent reading that record during ordinary triage treats the instruction as a legitimate finding and acts on it with its own already-granted access.

Why is GhostJacking hard to detect?

Because nothing about the delivery looks malicious. The firewall or monitoring tool already did its job and blocked or logged the attacker's request correctly; the attack is in what the log record says, not in any exploit or code execution. The agent then acts using valid, pre-issued credentials, so IAM, endpoint detection and the WAF itself have no anomaly to flag.

Which platforms has GhostJacking been demonstrated against?

Tenet Security's DEF CON 34 talk showed working chains against Cloudflare (a poisoned WAF log led an agent to hijack a DNS record), Datadog (a poisoned diagnostic log led to remote code execution) and Sentry (an injection moved from one AI agent's conclusion into a second, downstream agent that never saw the original text). Against Claude Code on Sonnet 4.6, the technique succeeded 9 of 10 times.

How do you defend against GhostJacking?

Security researchers quoted by VentureBeat argue the fix is an authorization gate outside the model: an agent may read logs, correlate alerts and draft a remediation, but a high-impact action such as a DNS change, a privilege change or a deployment requires a deterministic policy check and explicit human approval before it executes, rather than relying on prompt-based instructions the model can be talked past.

Sources

  1. GhostJacking Attacks: Half of the Fortune 500 Run These Tools. Getting Blocked by the Firewall Was the Way to Take Over Their AI AgentsTenet Security, 9 Aug 2026
  2. Ghostjacking Attack Uses Poisoned Logs to Turn AI Agents BadSecurityWeek
  3. The fix for the AI agent that hijacked a company's DNS: it can propose the change, but it can't approve itVentureBeat