{"slug": "ai-agent-misreads-hacker-message-proposes-dns-changes-without-approval", "title": "AI agent misreads hacker message, proposes DNS changes without approval", "summary": "Tenet Security researchers demonstrated at DEF CON 34 a new attack called 'Ghostjacking' that tricks AI coding agents into proposing DNS changes by planting malicious instructions in error logs, achieving a roughly 90% success rate against Claude Code setups. The attack exploits AI agents' default trust of data from platforms like Cloudflare, Datadog, and Sentry, and Tenet identified at least 48 organizations, including six Fortune 500 companies, with vulnerable MCP configurations. Tenet released an open-source mitigation tool called 'agent-jackstop' that denies outbound access for AI agents and requires explicit human approval for commands.", "body_md": "Photo: Tima Miroshnichenko / Pexels\n\n# AI agent misreads hacker message, proposes DNS changes without approval\n\nTenet Security's 'Ghostjacking' attack tricks AI agents into redirecting web traffic by hiding malicious instructions in error logs\n\nSecurity researchers have demonstrated a new class of attack that turns AI coding agents into unwitting accomplices. By planting malicious instructions inside ordinary error logs, attackers can trick AI agents into proposing DNS changes that redirect web traffic to domains controlled by hackers.\n\nThe technique, dubbed “Ghostjacking,” was unveiled at DEF CON 34 by Tenet Security researchers. It boasts a roughly 90% success rate against Claude Code setups.\n\n## How the attack works\n\nAI agents operating within platforms like Cloudflare, Datadog, and Sentry routinely ingest data from external tools: error logs, alerts, diagnostic outputs. Ghostjacking exploits the fact that these agents treat all of that input as trustworthy by default.\n\nAn attacker poisons the logs with carefully crafted instructions disguised as legitimate diagnostic commands. When an AI agent like Cursor running Claude Code reads that poisoned data, it interprets the malicious text as a real action item. The agent then proposes or attempts to execute DNS changes that would reroute a company’s web traffic to an attacker-controlled domain.\n\nTenet’s researchers demonstrated the attack across multiple platforms. Cloudflare was the headline target, but Datadog and Sentry were also turned into vectors for what the team described as operational sabotage. The researchers found thousands of exposed Datadog tokens and Sentry DSNs that could be exploited for log poisoning.\n\n## Who’s at risk\n\nTenet identified at least 48 organizations, including six Fortune 500 companies, running vulnerable MCP (Model Context Protocol) configurations that could be targeted by Ghostjacking.\n\nThe researchers were careful to note that the AI agent in their demonstration could suggest DNS changes but could not unilaterally approve them. In a well-configured environment, a human would still need to sign off.\n\n## The fix isn’t a patch\n\nTenet Security released an open-source mitigation tool called “agent-jackstop” alongside their DEF CON presentation. The tool works by denying outbound access for AI agents and requiring explicit human approval for commands. It also classifies all tool output as untrusted by default.\n\nThe researchers emphasized that Ghostjacking isn’t the kind of problem you solve with a software update. It’s a systemic design issue in how AI agents are architected and deployed.\n\nA separate but related issue involving a Claude Desktop sandbox escape was also noted by the researchers, though that vulnerability had been addressed before the DEF CON presentation.\n\n**Disclosure:** This article was edited by Editorial Team. For more information on how we create and review content, see our\n\n[Editorial Policy](https://cryptobriefing.com/editorial-policy/).", "url": "https://wpnews.pro/news/ai-agent-misreads-hacker-message-proposes-dns-changes-without-approval", "canonical_source": "https://cryptobriefing.com/ai-agent-ghostjacking-dns-attack/", "published_at": "2026-08-26 16:20:00+00:00", "updated_at": "2026-08-26 16:43:47.422162+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-policy"], "entities": ["Tenet Security", "DEF CON 34", "Claude Code", "Cloudflare", "Datadog", "Sentry", "agent-jackstop", "MCP"], "alternates": {"html": "https://wpnews.pro/news/ai-agent-misreads-hacker-message-proposes-dns-changes-without-approval", "markdown": "https://wpnews.pro/news/ai-agent-misreads-hacker-message-proposes-dns-changes-without-approval.md", "text": "https://wpnews.pro/news/ai-agent-misreads-hacker-message-proposes-dns-changes-without-approval.txt", "jsonld": "https://wpnews.pro/news/ai-agent-misreads-hacker-message-proposes-dns-changes-without-approval.jsonld"}}