'Ghostjacking' Shows How Attackers Can Turn Trusted Data Into AI Commands

August 13, 2026
'Ghostjacking' Shows How Attackers Can Turn Trusted Data Into AI Commands
IANS News

Key Points

  • A new AI hijacking attack -- dubbed Ghostjacking -- demonstrates how threat actors can hide malicious instructions in trusted logs, alerts, and monitoring data to manipulate AI agents into taking unauthorized actions.
  • The research highlights a broader issue in agentic AI systems: agents often cannot distinguish attacker-controlled content from legitimate information and may act on it using their authorized permissions.
  • IANS Faculty recommend keeping AI agents that ingest logs and alerts read-only, assigning them unique least-privilege identities, and requiring human approval for high-impact infrastructure changes.

 

'Ghostjacking' Shows How Attackers Can Turn Trusted Data Into AI Commands

A new AI hijacking attack, dubbed Ghostjacking, uses poisoned logs and alerts to manipulate AI agents into taking unauthorized actions.

The findings from cybersecurity startup Tenet expand on its previous Agentjacking research, which demonstrated how attackers could hijack coding agents by tricking them into running malicious code on developer machines.

Ghostjacking, which was presented by Tenet researchers at DEFCON, follows a similar attack structure -- where threat actors place instructions deep within trusted operational sources (like logs, alerts, or monitoring data) to silently corrupt AI agents and manipulate their behavior.

The researchers demonstrated how the attack could be replicated across three different highly trusted platforms: Cloudflare, Datadog, and Sentry.

Because AI agents are built to process data from systems they can access and act on it, Ghostjacking exploits their difficulty distinguishing untrusted content from trusted sources, allowing attackers to hide malicious commands inside legitimate sources.

"The attack surface is larger than most teams expect: firewall and WAF block logs, IDS alerts, error trackers, abuse and phishing mailboxes, fraud alerts, support tickets, vendor bulletins. Tenet found more than 2,700 exposed Datadog front-end keys, and Sentry identifiers are public by design, so treat those systems as open to anyone and limit what an agent may do with whatever it reads back.”  Jeff Brown, IANS Faculty.

Tenet researchers said the problem is not a specific vulnerability, but overly trusting agents that treat external information as reliable.

“Ghostjacking is an attack that runs entirely on actions the AI was authorized to take, using internal agents’ tools and actions, nothing out of behavior, no need for code execution, so nothing ever trips an alarm,” said the report.

 

Big Picture

Ghostjacking exposes a fundamental design challenge in agentic systems: agents inherently trust data from operational tools because they lack the context needed to distinguish attacker-manipulated content from legitimate instructions.

"The moment one agent can both read a security log and change production, every field an outsider can write to becomes a command line, and the firewall block that dutifully records the attempt becomes the delivery mechanism.”  Jeff Brown, IANS Faculty.

The attack underscores why security teams must remain skeptical of how agents interact with telemetry, logs, and alerts. Because agents can be manipulated by attacker-controlled telemetry, security data can no longer be treated as inherently trustworthy input for AI systems.

"The SOC and IR folks need to be aware of this attack vector. This means there also needs to be a human in the loop reviewing these alerts and logs that aren’t going to then run it through an LLM that will give false information -- that could also potentially lead to these configurations. We're not ready for a fully autonomous SOC precisely because of things like this.”  Jessica Hebenstreit, IANS Faculty.

If agents can be turned into attack channels, organizations need to be more intentional at setting specific trust boundaries and accountability chains to keep them in check.

"The exposure executives should care about is not just unauthorized change; it's attribution collapse. In a regulated firm that becomes a change-control finding, a materiality assessment nobody has the evidence to complete, and eventually a question about who owns an action an agent took using a human's credentials.”  Jeff Brown, IANS Faculty.

 

IANS Faculty Recommendations

  • Separate AI analysis from execution: Keep agents that ingest logs, alerts and other untrusted data read-only and block their access to identity systems, DNS, deployment pipelines and production.
  • Inventory untrusted inputs into AI agents: Map every external source that can feed content into an agent, including security logs, support tickets, phishing mailboxes, error trackers and vendor alerts. Treat externally writable sources as untrusted and restrict what actions agents can take based on that data.
  • Assign every agent a unique identity: Give agents dedicated, least privilege credentials instead of allowing them to inherit user or service-account access. Log agent and human activity separately so security teams can determine exactly what an agent accessed, changed or triggered during an incident.
  • Require human approval for high-impact infrastructure changes: Prevent agents from autonomously modifying DNS, domain registrar settings, certificates and other controls that could redirect customer traffic or communications.


Authors & Contributors

Emily Dempsey, Author - Security Reporter, IANS News

Jeff Brown, IANS Faculty

Jessica Hebenstreit, IANS Faculty

 

Although reasonable efforts will be made to ensure the completeness and accuracy of the information contained in our News & blog posts, no liability can be accepted by IANS or our Faculty members for the results of any actions taken by individuals or firms in connection with such information, opinions, or advice.

Subscribe to IANS Blog

Receive a wealth of trending cyber tips and how-tos delivered directly weekly to your inbox.

Please provide a business email.