← Back to feed
AI SecurityEmerging1 sourceAug 11, 2026 · 10:33via Cyber Security News

New ‘Ghostjacking’ Attack Lets Hackers Hijack AI Agents to Run Their Code on Developer Machines

Brief

A new AI-agent attack technique called “Ghostjacking,” can trick coding agents into running attacker-controlled commands, changing cloud settings, stealing credentials, and creating persistent backdoors.

The research was presented by Tenet Security at DEF CON 34 in Las Vegas on August 9, 2026. Tenet said the attack affects a growing class of AI-enabled workflows in which coding assistants can read information from trusted tools and then take action in development or cloud environments.

Ghostjacking is based on indirect prompt injection . Instead of sending a malicious command directly to an AI coding assistant, an attacker embeds harmful instructions in data the agent is likely to inspect. This could include a blocked web request, an error log, a monitoring alert, or a bug report.

Read more on Cyber Security News