The attack that hijacked Claude Code came through Sentry. Datadog, PagerDuty, and Jira have the same exposure.
Source:
ventureBeat
June 29, 2026 · 09:53
A single fake error report hijacked Claude Code in controlled testing — the agent ran the attacker's code with the developer's full privileges, and not one alert fired. EDR, WAF, IAM, and the firewall all missed it completely.Tenet Security's June agentjacking disclosure describes a single crafted Sentry error event — sent through a public credential that requires no breach and no authentication — that injected attacker instructions into error data that Claude Code, Cursor, and Codex then executed as trusted diagnostic output. Tenet tested 100-plus targets in controlled conditions and achieved an 85% success rate. Sentry called the flaw "technically not defensible."he Cloud Security Alliance classified agentjacking as a systemic MCP vulnerability class within days of the disclosure. No cre…
The original article opens on the publisher's website.
More from Mobile
View topic →China dissented from G20 statement opposing 'cheap exports' flooding market, Bessent says
cnbc
Sep 1, 2026 · 16:52
Android stuck in Safe Mode? Here's how to turn it off
engadget
Sep 1, 2026 · 16:00
How to change the background on iPhone Messages
engadget
Sep 1, 2026 · 15:30
US diesel prices soar as Trump hauls in refiners
financialTimes
Sep 1, 2026 · 14:18
Google’s Android update tackles motion sickness, accessibility, and more
techcrunch
Sep 1, 2026 · 13:53