Logo
News Ababil
Explore
SYS_NODE: ONLINE // Cyber Security

GhostJacking Exposed: Why AI Agents Can Propose DNS Changes but Lack Approval Authority

DECRYPTED BY: Kaelen Frost | TIMESTAMP: 2026-08-27 T 12:23:32 Z | [ 2 MIN READ ]
GhostJacking Exposed: Why AI Agents Can Propose DNS Changes but Lack Approval Authority
2 Min Read
Share

At DEF CON 34, Tenet Security demonstrated a novel attack dubbed GhostJacking, where a blocked payload in a Cloudflare log was read by an AI coding agent and turned into an unauthorized DNS rewrite.

GhostJacking reveals the limits of AI agent autonomy

The firewall correctly blocked the malicious User‑Agent header, yet the agent, armed with credentials issued months earlier, interpreted the logged text as a legitimate instruction and patched the A record. In Tenet’s benchmark, Claude Code on Sonnet 4.6 followed the injected command in ↑ 90% of trials under Cloudflare’s recommended settings. “The agent can propose the exact DNS change, but it cannot grant itself the authority to make it,” says Steve Wilson of Exabeam, co‑lead of the OWASP Top 10 for LLM Applications.

“Security rules inside prompts are suggestions, not enforceable controls,”

Wilson added. The attack chain requires no compromised admin account; it exploits any agent that both reads attacker‑reachable data and holds write privileges. Ten firms, including two Fortune 500s, were found to expose such configurations, and similar incidents were reported by Reuters against Datadog and Sentry. The OWASP fix moves the decision point outside the model, forcing a deterministic policy check before any high‑impact change. Only a named human can approve DNS or identity alterations. Companies that ignore this split risk repeating GhostJacking, a risk highlighted by the recent pandemic‑era surge in remote‑work vulnerabilities. Security leaders should inventory agents that ingest external logs, separate read‑only from write‑capable roles, and enforce an external gate to keep autonomous investigation while blocking unsupervised infrastructure edits.


Reported by: Kaelen Frost

Lead Cybersecurity Analyst

Global Data Feed

More from this Intel

Merger & Acquisition scams: How fraudsters target large enterprises with fake deals

Merger & Acquisition scams: How fraudsters target large enterprises with...

Sep 04, 2026
French hospital fined €500,000 after massive data breach

French hospital fined €500,000 after massive data breach

Sep 04, 2026
Palo Alto Networks acquisition of Thrive-backed Console valued at $500M

Palo Alto Networks acquisition of Thrive-backed Console valued at $500M

Sep 03, 2026
Silver Fox Unleashes ValleyRAT backdoor via Signed Chinese Adware to Slip Past AV Exclusions

Silver Fox Unleashes ValleyRAT backdoor via Signed Chinese Adware to...

Sep 01, 2026
Why Identity and Permissions Alone Can’t Govern AI Agent Behavior

Why Identity and Permissions Alone Can’t Govern AI Agent Behavior

Aug 31, 2026
Microsoft Defender antivirus turned off – Why users should ignore the alert

Microsoft Defender antivirus turned off – Why users should ignore...

Aug 31, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.