Research · curated 10 Aug 2026
'GhostJacking' Exposes Identity Governance Gaps in AI Agents
First reported darkreading.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
GhostJacking demonstrates that AI agents can be hijacked by poisoning the very telemetry and security-alert data they trust, exploiting their legitimate access and privileges and exposing identity-governance gaps defenders must address.
Tenet Security presented 'GhostJacking' research at DEF CON 34, showing how attackers can poison content in trusted systems such as security alerts, logs, and error reports to trick AI agents into executing code, stealing credentials, or achieving infrastructure takeover. The work expands the company's earlier 'Agentjacking' technique into a broader attack model spanning multiple trusted data sources and damaging actions.