Threat · curated 1 Jul 2026

Fake Bug Report Hijacks AI Coding Agents at Scale

Coverage timeline

discovered tenetsecurity.ai primary 15 Jun 2026devops.com 30 Jun 2026darkreading.com

Why it matters

Agentjacking shows that AI coding agents' inability to distinguish content from instructions turns routine developer tooling like Sentry into a scalable code-execution and credential-theft vector that existing security stacks cannot see.

Tenet Security demonstrated "agentjacking," an indirect prompt-injection technique in which an attacker plants a single fake error report in a public bug-tracking service (Sentry) that hijacks AI coding agents into running attacker-controlled code on a developer's machine. In controlled testing, widely used assistants including Claude Code, Cursor, and Codex retrieved the poisoned error data and, in many cases, executed the code, opening a path to theft of cloud credentials, AWS keys, GitHub tokens, SSH keys, and CI/CD secrets.