Observed Signal · Jul 1, 2026 · Security Research · Source: t3n · Impact: 3/5 · Sentiment: Negative
Agentjacking: Fake Bug Reports Hijack AI Agents
Security firm Tenet Security describes a new attack class called “Agentjacking” in which manipulated crash/bug reports delivered via tracking tools (e.g., Sentry) can covertly hijack AI coding assistants. Attackers send specially crafted error reports to publicly accessible endpoints (Data Source Name/DSN) that include hidden Markdown-formatted instructions. Because current AI agents and model integrations do not reliably distinguish passive textual data from executable instructions when ingesting external data via protocols such as the Model Context Protocol (MCP), the agent can fetch and execute embedded code on developers’ machines. Tenet reports an 85% success rate across tests with over 100 organisations. Sentry has acknowledged the issue but said a root-cause fix on the platform is not feasible; Tenet recommends restricting agent execution rights and requiring human approval for critical commands.
The vulnerability enables widespread compromise of developer machines and sensitive assets via commonly used agent integrations (MCP/Sentry), undermining trust in agentic tooling and forcing changes to execution permissions and runtime security controls.
Track Sentry Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Tenet Security identified and named the attack class 'Agentjacking', where manipulated error reports can hijack AI coding agents.
- Attacks use publicly accessible endpoints (DSNs) and the Model Context Protocol to deliver specially crafted crash reports (e.g., to Sentry) containing hidden Markdown instructions.
- Tenet Security's investigation demonstrated the method worked across more than 100 organisations with an 85% success rate, including a very large technology company.
- Sentry confirmed the underlying problem can occur on its platform but stated that a root-level mitigation on the platform side is 'technically not defensible'.
- Tenet Security (Barak Sternberg) recommends massively restricting execution rights of AI assistants and enforcing manual human approval for critical system commands.
Connected Companies & Entities
2 Entities mapped“An attacker sends via a publicly accessible endpoint (a so-called Data Source Name) a specially crafted crash report to the service of the U...”
“Here you find external content from TargetVideo GmbH, which supplements our editorial offering on t3n.de....”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
AI Code Reviewers Ran Malware via Context Poisoning
Researchers published multiple proof-of-concept attacks showing autonomous coding agents will execute attacker-supplied instructions embedded in untrusted text. The AI Now Institute disclosed "Friendly Fire," where a README instructs an agent to run a malicious security.sh script; Tenet disclosed "Agentjacking," which used a fake Sentry bug report (reported 85% hit rate) to trick agents; and Noma Security demonstrated "GitLost," which made a GitHub Agentic Workflow leak private repository content to a public issue. The author reports running similar agentic pipelines (Claude Code in autonomous mode) and describes mitigations — filesystem isolation, scoping agent access to single repos, and pinning agent versions — while stressing there is no complete fix: the root cause is agents following in-scope text instructions. Publication date: 2026-07-13.
Ghostjacking: Logs Turned into Commands for AI Agents
Security researchers published a proof-of-concept called "ghostjacking" showing how attackers can embed natural-language commands into logs, alerts, and issue trackers so AI agents with read and write permissions will execute those commands. The PoC chains target systems like Cloudflare WAF logs, Datadog alerts, and Sentry reports to cause DNS changes, execute shell commands, steal cloud credentials, propagate commands to other agents, and persist backdoors in agent memory or configs. Tests used researcher-controlled accounts and public APIs; no CVE has been published and Claude Desktop’s sandbox bypass was reported to Anthropic and patched. The report outlines success/failure conditions, detection signals, MITRE mappings, and an investigation/containment playbook for SOCs and administrators.
AI Agents Enable Fully Autonomous Cyber Intrusions
An independent OSINT-based cyber threat analysis published 2026-05-30 documents five related incidents from late May 2026 that indicate a shift in attacker tradecraft: AI is moving from a human-accelerating tool to an autonomous operator and an exploitable attack surface. Notable cases include a Sysdig-documented Marimo notebook compromise (CVE-2026-39987, CVSS 9.3) where an LLM agent autonomously executed a multi-stage pivot and dumped an internal PostgreSQL database; ChatGPhish, a prompt-injection-style attack against ChatGPT’s renderer disclosed by Permiso Security; Wiz’s JINX-0164 supply-chain and dev-infrastructure attacks against crypto targets (macOS RATs, trojanized npm package @velora-dex/sdk); Rapid7’s unauthenticated-to-RCE chain in Gogs (CVSS 9.4, reported 2026-03-17) with a public Metasploit module and ~1,141 internet-exposed instances; and a KelpDAO/LayerZero bridge compromise illustrating off-chain verifier single points of failure. The author emphasizes reducing trusted dependencies, isolating credentials, runtime behavioral detection, and treating AI output as the start—not the end—of verification.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
