GhostJacking: the fix for AI agents that hijack DNS | VentureBeat

https://images.ctfassets.net/jdtwqhzvc2n1/28m7aTuL4ti8gVOmBav4Od/54a57f5f3c018f6060177e2d4e971400/hero2.png?w=800&q=75

A security agent read a Cloudflare log, found an attacker’s prompt-injection payload sitting inside it, and rewrote the company’s DNS. The firewall had already blocked that payload, and blocking it is what wrote it into the log.

That chain is GhostJacking, which Tenet Security demonstrated on the DEF CON 34 main stage on August 9. A request hits Cloudflare’s managed ruleset, gets blocked, and is stored byte for byte with its poisoned User-Agent header. An AI coding agent reviewing those blocked events reads the attacker's text as an instruction — with no way to tell it apart from one the company meant to give it — and acts on it with credentials the company issued months earlier. In Tenet’s benchmark, Claude Code on Sonnet 4.6 followed the planted instruction in nine of 10 attempts under Cloudflare’s recommended configuration.

The block rate is not the boundary

Nothing malfunctioned. The firewall...

Copyright of this story solely belongs to venturebeat.com. To see the full text click HERE

Read more