The fix for the AI agent that hijacked a company's DNS: it can propose the change, but it can't approve it
Source:
ventureBeat
August 26, 2026 · 09:13
A security agent read a Cloudflare log, found an attacker’s prompt-injection payload sitting inside it, and rewrote the company’s DNS. The firewall had already blocked that payload, and blocking it is what wrote it into the log.That chain is GhostJacking, which Tenet Security demonstrated on the DEF CON 34 main stage on August 9. A request hits Cloudflare’s managed ruleset, gets blocked, and is stored byte for byte with its poisoned User-Agent header. An AI coding agent reviewing those blocked events reads the attacker's text as an instruction — with no way to tell it apart from one the company meant to give it — and acts on it with credentials the company issued months earlier. In Tenet’s benchmark, Claude Code on Sonnet 4.6 followed the planted instruction in nine of 10 attempts under Cl…
The original article opens on the publisher's website.
More from Automotive
View topic →Larry Page’s flying car company Pivotal loses its CEO
techcrunch
Sep 1, 2026 · 16:59
SEC proposes transfer agent rule, sets event to figure out round-the-clock U.S. trading
coinDesk
Sep 1, 2026 · 16:55
China dissented from G20 statement opposing 'cheap exports' flooding market, Bessent says
cnbc
Sep 1, 2026 · 16:52
The Range Rover Electric: Specs, Price, Availability
wired
Sep 1, 2026 · 16:01
Blue Origin wins NASA contract for telecommunications on Mars
engadget
Sep 1, 2026 · 16:00