Analysis
After GHOSTJACKING: What Agent Security Hardening Actually Requires
First reported · Discovered forkast.news
Page published
Earliest dated coverage: 7 Oct 2026 · First observed: 9 Oct 2026 · Latest dated coverage: 7 Oct 2026
Coverage timeline
Single-source analysis — one report is available.
Why it matters
GHOSTJACKING-style indirect prompt injection and agent-goal-hijack (OWASP ASI01) are the top agentic risk, and this analysis stresses that defenders must shift from detection to restricting agent action because malicious actions often appear legitimate.
Forkast analyzes the fallout from GHOSTJACKING, an indirect prompt injection attack against AI agents formalized in an ngCERT advisory (October 6, 2026) that recommends nine structural hardening steps such as deny-by-default egress, human-in-the-loop approval, and least-privilege MCP servers. The piece argues enterprise inertia—low adoption of defensive configs like Tenet Security's agent-jackstop, lack of formal AI policy, and shadow-agent sprawl—is a governance failure, citing Tenet's Agentjacking demo that hijacked over 100 agents at a Fortune 100 company via injectable Sentry DSNs.