AI agents2026-08-26 22:25:19Tenet Security unveils Ghostjacking attack that can steer AI agents into DNS hijacksTenet Security disclosed a new attack technique called "Ghostjacking" at DEF CON 34, saying it can successfully target AI agents such as Claude Code at rates of up to 90%. The attack works by planting malicious instructions inside error logs on platforms including Cloudflare and Datadog. Those instructions can prompt an AI agent to suggest DNS configuration changes, which then redirect traffic to domains controlled by an attacker. The security team said it has identified at least 48 organizations running vulnerable MCP configurations, including six Fortune 500 companies. To address the issue, Tenet Security released an open-source mitigation tool named "agent-jackstop." The tool is designed to limit outbound access by AI agents and require human review before commands are carried out. Researchers said the problem reflects a systemic design flaw in AI agent architecture rather than a conventional software bug. The disclosure was cited by CryptoBriefing.900