Claude Code hijacked via Sentry — Datadog, PagerDuty at risk | VentureBeat

https://images.ctfassets.net/jdtwqhzvc2n1/6di1wa5fhWEfFyVhOuFc0/d26a92a3d31716e3c020864f400459f0/hero.png?w=800&q=75

A single fake error report hijacked Claude Code in controlled testing — the agent ran the attacker's code with the developer's full privileges, and not one alert fired. EDR, WAF, IAM, and the firewall all missed it completely.

Tenet Security's June agentjacking disclosure describes a single crafted Sentry error event — sent through a public credential that requires no breach and no authentication — that injected attacker instructions into error data that Claude Code, Cursor, and Codex then executed as trusted diagnostic output. Tenet tested 100-plus targets in controlled conditions and achieved an 85% success rate. Sentry called the flaw "technically not defensible."

he Cloud Security Alliance classified agentjacking as a systemic MCP vulnerability class within days of the disclosure. No credentials were stolen, no policy was violated, no perimeter was breached: every step in the chain was authorized. That is the problem.

Tenet identified 2,388 organizations with publicly exposed...

Copyright of this story solely belongs to venturebeat.com. To see the full text click HERE

Read more

https://d15shllkswkct0.cloudfront.net/wp-content/blogs.dir/1/files/2026/06/Screenshot-from-2026-06-29-07-21-33.png

Baz releases Baz Planner, which uses four specialized AI agents to analyze code at the planning stage, and extends its seed funding by $9M to $17M

Sponsor Posts Fast, affordable law for startups — Soxton automates startup legal so founders can move faster and sleep better. We handle incorporation, advisor, employment and commercial contracts. Join the waitlist for early access! Stop vibe coding analytics — Equals AI turns questions about your business into auditable spreadsheet models and dashboards.