Threat

ngCERT GHOSTJACKING Advisory Formalizes Agentjacking — MCP Integrations Now a Government-Level Threat

Page published

Earliest dated coverage: 6 Oct 2026 · First observed: 9 Oct 2026 · Latest dated coverage: 6 Oct 2026

Coverage timeline

6 Oct 2026forkast.news

Single-source advisory — one report is available.

Why it matters

Ghostjacking shows that MCP integrations' implicit-trust design lets attacker-controlled data drive authorized agent actions that bypass conventional detection, and a national CERT now treats it as a government-level threat affecting widely deployed coding agents.

Nigeria's ngCERT issued an October 6, 2026 advisory formalizing 'Ghostjacking' (also called Agentjacking) — an indirect prompt injection against AI agents via Model Context Protocol (MCP) integrations such as Cloudflare, Datadog, and Sentry, where agents treat retrieved external data as trusted instructions and execute in-scope actions like code execution and cloud credential theft that evade EDR, WAF, and IAM. Tenet Security researchers demonstrated 85-90% exploitation success rates against Claude Code, Cursor, and Codex (notably via Sentry DSN injection), audited 2,388 organizations with injectable public Sentry DSNs, and released an open-source hardening tool, agent-jackstop; Anthropic patched a separate Claude Desktop egress-sandbox JWT reuse zero-day before DEF CON 34.