Poisoned logs turn trusted platforms into agent hijackers

Tenet Security's Ghostjacking demo shows attackers planting instructions in logs that AI agents read and execute, targeting Cloudflare, Datadog, and Sentry.

CSBadmin
2 Min Read

The logs and alerts that AI agents read for context are becoming a delivery channel for attacks, according to research unveiled at DEF CON. Tenet Security calls the technique Ghostjacking: an intruder plants text instructions inside routine operational data, and an agent that trusts that data carries them out.

The three demonstrations all lean on widely deployed infrastructure. Cloudflare handles roughly 20 percent of web traffic, Datadog and Sentry both serve massive enterprise customer bases, and each platform’s logging pipeline accepts user-controlled content that an agent may later interpret as commands.

Against Cloudflare, the researchers found that a firewall-blocked request is recorded verbatim, so attacker text lands in the log as plain content. A security analyst who then asks an agent to explain the event hands the model the embedded instructions; the demo showed DNS records being redirected to a hostile domain while the agent reported everything as resolved. Tenet’s own tests succeeded against Claude Code in nine of ten attempts.

For Datadog, the weak point is front-end API keys that get left exposed, with Tenet locating more than 2,700 of them online. Using one, an attacker posts a fabricated urgent alert; an engineer who tells the agent to hunt for errors gets the agent running the planted command instead. In the demonstration, Claude Code wound up running attacker code and sending environment secrets and cloud credentials out of the environment.

Sentry’s AI assistant Seer provided the third path: a tampered report makes Seer adopt a malicious proposed fix, and a downstream coding agent that trusts Seer executes it.

Tenet also demonstrated agents attacking other agents, refining refusal responses until the target model carried out the attack on itself.

The finding extends the startup’s earlier Agentjacking work as organizations deploy agents that read first and verify later.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.