AnalysisCybersecurityAugust 10, 2026

'Ghostjacking' Attack Uses Poisoned Logs to Turn AI Agents Bad

Tenet researchers demonstrated the attack at DEF CON, planting malicious instructions in logs from Cloudflare, Datadog, and Sentry that AI agents trust and execute. It worked 9 of 10 times against Claude Code, hijacking domains and stealing cloud credentials. Cloudflare's managed security rule logs blocked requests word for word, carrying the attacker's instructions in.

1 source

Daily brief

Get tomorrow's AI brief in your inbox

More stories today

Open the live feed