2026/08/26/the-fix-for-the-ai-agent-that-hijacked-a-companys
The fix for the AI agent that hijacked a company's DNS: it can propose the change, but it can't approve it

편집자 요약
Tenet Security는 DEF CON 34에서 Cloudflare가 차단한 요청 로그에 남은 공격자 User-Agent가 AI coding agent에 의해 명령으로 해석돼 DNS 변경까지 이어지는 GhostJacking 체인을 시연했습니다. 벤치마크에서 Claude Code on Sonnet 4.6은 Cloudflare 권장 설정하에서도 10회 중 9회 삽입된 지시를 따랐으며, 방화벽·EDR·IAM은 모두 정상 동작한 것으로 나타났습니다.
인사이트
핵심은 prompt injection 차단률이 보안 경계가 될 수 없다는 점입니다. agent가 공격자가 도달할 수 있는 데이터를 읽고 동시에 고위험 변경 권한을 보유하면, 유효한 자격 증명으로 수행되는 행위는 기존 탐지 체계를 우회할 수 있습니다. 따라서 agent는 변경을 제안만 하고 실행 승인은 모델 밖 코드와 사람에게 맡기는 권한 분리가 AI 운영 보안의 기본 패턴으로 자리 잡을 전망입니다.
댓글
토론
> geekhaus:~$ 다음 읽을거리?
다음 읽을거리 추천

VentureBeat
Salesforce just put its entire CRM inside Claude — and says you’ll never need its app again

VentureBeat
Prompt injection ranks No. 1 with OWASP and No. 12 in the incident record. The attack itself is invisible to a scan.

VentureBeat