# Firewall Blocks the Attack. Then the AI Agent Lets It Back In.
A Cloudflare firewall caught a malicious request and logged it — doing exactly what it was supposed to do. Then an AI agent read that log, and the attacker got everything they wanted anyway.
That's the core of GhostJacking, a technique demonstrated at DEF CON 34 this week by researchers at Tenet Security. The setup sounds almost absurd: the very act of blocking an attack becomes the delivery mechanism for a second, more dangerous one. But there's nothing absurd about the implications. If AI agents are reading your security telemetry and acting on it — and in 2026, a lot of them are — your monitoring stack just became an attack surface.
## The Invisible Hand in the Log File
GhostJacking is an evolution of Agentjacking, Tenet's earlier research from June that showed how attackers could poison trusted telemetry to manipulate AI coding assistants. The new work is broader: more platforms, more attack paths, more damage.
The fundamental mechanism is indirect prompt injection. AI agents are built to consume data from monitoring tools, error trackers, and security platforms — then take action on what they find. When Tenet planted malicious instructions inside a Cloudflare firewall log entry, the agent didn't see an attacker. It saw a log it was supposed to process. It acted accordingly, modifying DNS settings and handing the domain to the attacker.
The researchers ran the same pattern against Datadog and Sentry. Different platforms, same result. This isn't a Cloudflare problem or a Datadog problem. It's a category problem: any AI agent that reads external data and acts on it is potentially exploitable through that data.
The hit rate against Claude Code was nine out of ten. That number deserves sitting with for a moment. This isn't a theoretically exploitable edge case. It's a technique that works almost every time against one of the most widely deployed AI coding assistants on the market.
## Why Agents Fail the Trust Test
Human analysts reading a firewall log don't typically execute the requests inside it. They understand, implicitly, that the log is a record of something that happened — not an instruction. This distinction, obvious to anyone who's spent five minutes in a SOC, is exactly the distinction AI agents struggle to make.
The problem has a name in the research community: instruction-content confusion. Agents lack reliable mechanisms for tracking where data came from and what trust level to assign it. A blocked request logged by Cloudflare looks, to a naive agent, much like a legitimate instruction from a trusted system. The attacker's job is just to format the malicious content in a way that resembles the patterns the agent has learned to act on.
What makes GhostJacking especially clean is that it doesn't require compromising the monitoring platform itself. The attacker just needs to trigger an event that gets logged — a blocked web request, a rate-limit hit, a failed authentication attempt. The platform does its job. The agent does not.
## The Permissions Problem Nobody Fixed
Every AI agent has permissions. It can call APIs, modify configurations, execute code, read credentials. Those permissions were granted because the agent needs them to do its job. GhostJacking weaponizes that legitimacy: the agent uses its real access to do the attacker's bidding.
This is the identity governance gap in the research title, and it's one that's been papered over in the rush to deploy agentic AI. Organizations set up agents with broad operational permissions, then trust that because the agent is acting on "legitimate" data from "trusted" systems, everything it does is above board. GhostJacking shows that trust chain snaps at the exact point where external data enters the loop.
The fix isn't straightforward. You can't just tell an agent "trust this system less" — the whole point of agentic architectures is that the agent takes inputs from multiple sources and synthesizes them. What you need are agents that maintain strict provenance tracking for every piece of data they process, treat untrusted content as read-only regardless of where it came from, and require explicit confirmation before taking high-impact actions based on data sourced from external systems.
Most production agent deployments today have none of these.
## What Defenders Should Do Right Now
The organizations most exposed are those running AI agents with access to infrastructure controls — DNS, firewall configuration, code deployment, cloud resource management — that also feed those agents from external data sources. That describes a lot of security operations tooling built in the last eighteen months.
Immediate mitigations:
The DEF CON disclosure gives defenders a window. It won't stay open long.
---
## HackWire Analysis
GhostJacking lands at a specific and uncomfortable moment: the industry is deploying AI agents for security operations faster than it's developing the governance frameworks to run them safely. That tension isn't new — every major security technology wave has had it — but the stakes here are unusually high because these agents have real privileges in production environments.
What the research reveals isn't a clever zero-day. It's a structural problem that's been hiding in plain sight. The entire value proposition of AI security agents is that they can consume telemetry at machine speed and act on it. That's also the attack surface. You can't have one without the other unless you've built real trust boundaries into the architecture — and most agentic platforms, including the major commercial ones, have not.
The nine-out-of-ten success rate against Claude Code should be read as a benchmark, not an indictment of a single vendor. The industry needs to treat that number as a challenge to beat, publicly, with verifiable testing. Anthropic has been better than most on responsible disclosure and security research engagement; the question is whether they and others move fast enough on the architecture fixes before GhostJacking-style techniques show up in actual intrusions.
The Agentjacking-to-GhostJacking evolution in two months also signals something: researchers are iterating quickly on this class of attack. Organizations deploying agents with infrastructure access today are doing so in an environment where the offensive research community is actively trying to break those exact systems. That risk calculus deserves more weight than it's currently getting in most AI adoption decisions.
The monitoring stack being the attack surface is going to look obvious in retrospect. It always does.
— HackWire Editorial
---
## Related Coverage