A newly revealed "Ghostjacking" attack pattern exploits trusted operational data such as blocked web requests and monitoring alerts within enterprises This article explores agent read attacker. . The research, presented by Tenet Security at DEF CON 34, highlights that this risk is architectural: an agent can read attacker-controlled content and exercise legitimate access to the same environment.
When an analyst asks an AI assistant to investigate these events, the agent may interpret embedded attacker text as instructions rather than untrusted evidence. New GhostJacking Attacks Target AI Agents via Cloudflare Configuration Changes If the assistant configures Cloudflare, researchers revealed it could modify DNS records directing victims' domains to attacker-controlled infrastructure.
In the Sentry case, the company's Seer AI accepted a maliciously framed remediation and passed that conclusion to another coding agent, creating an agent-to-agent trust hop. It includes privilege escalation from developer workstations toward core cloud or domain administration, credential theft, and persistence through changes to agent configuration, memory, or tool definitions. Their permissions enable significant alterations, yet language models inherently blend log data with hidden instructions.
They should default to denying outbound agent network access, requiring human approval for commands and high-impact changes, isolating read-only investigation from write-capable operations, and issuing short-lived, narrowly scoped credentials. Enhance your Security Operations Center (SOC) by gaining comprehensive phishing insights, thereby reducing Mean Time To Resolution (MTTR).












