A novel "Ghostjacking" attack technique has been identified, enabling attackers to manipulate and control AI-driven coding agents via subtle manipulation of cloud environments or development workflows This article explores attackers ai agent. . This stealthy method exploits indirect prompt injection, where malicious instructions are concealed within data that the AI-assisted coder is anticipated to scrutinize.
If the agent has access to shell commands, cloud dashboards, DNS records, source code, or secrets, it might perform dangerous actions using permissions already granted by the organization. The firewall successfully intercepted the unauthorized request, yet when an analyst tasked an AI assistant with reviewing the logged event, the assistant inadvertently processed and analyzed the attacker's manipulated text within the logs.
Researchers revealed attackers could exploit publicly accessible client-side keys to generate fake alerts that appear urgent with deceptive diagnostic instructions. The Sentry attack chain specifically targeted trust between AI systems, focusing on how Seer—an AI assistant—could analyze crafted issue reports to produce recommendations under the control of attackers. The AI agent executes authorized tasks, making it more difficult for endpoint detection tools, web application firewalls, and identity systems to identify it as malicious.
Tenet suggests defaulting access restrictions on AI agents, requiring human approval before executing commands, separating untrusted data from instructions, and reviewing every token and external tool used in an AI workflow.












