Research · curated 10 Aug 2026

'GhostJacking' Exposes Identity Governance Gaps in AI Agents

Coverage timeline

10 Aug 2026darkreading.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

GhostJacking demonstrates that AI agents can be hijacked by poisoning the very telemetry and security-alert data they trust, exploiting their legitimate access and privileges and exposing identity-governance gaps defenders must address.

Tenet Security presented 'GhostJacking' research at DEF CON 34, showing how attackers can poison content in trusted systems such as security alerts, logs, and error reports to trick AI agents into executing code, stealing credentials, or achieving infrastructure takeover. The work expands the company's earlier 'Agentjacking' technique into a broader attack model spanning multiple trusted data sources and damaging actions.