Research · curated 10 Aug 2026

"GhostJacking" Exposes Identity Governance Gaps in AI Agents

Coverage timeline

10 Aug 2026securityweek.comdarkreading.com

Why it matters

GhostJacking shows that AI agents inherit and can be turned against their own privileged access when they ingest attacker-poisoned telemetry, exposing identity-governance and guardrail gaps defenders must close around agentic systems.

Tenet Security presented "GhostJacking" research at DEF CON 34, demonstrating how attackers can poison content in trusted systems such as security alerts, logs, and error reports to trick AI agents into executing code, stealing credentials, and taking over infrastructure. The work expands the company's earlier "Agentjacking" technique into a broader attack model spanning multiple trusted data sources and a wider range of damaging agent actions.