GEEK HAUS
Back to feed

The fix for the AI agent that hijacked a company's DNS: it can propose the change, but it can't approve it

·VentureBeat
read original
The fix for the AI agent that hijacked a company's DNS: it can propose the change, but it can't approve it

EDITOR BRIEF

Tenet Security demonstrated GhostJacking, a prompt-injection chain where an attacker’s blocked request is stored in Cloudflare logs and later interpreted by an AI coding agent as an instruction. In its benchmark, Claude Code followed the planted command in nine of 10 attempts, using valid credentials to rewrite DNS even though the firewall had worked as intended.

INSIGHTS

The incident shows that blocking malicious input is not enough when AI agents later consume attacker-controlled logs, alerts, or error reports. The emerging best practice is an external authorization gate: agents may propose sensitive changes, but separate deterministic systems or humans must approve execution.

COMMENTS

Discussion

> geekhaus:~$ next read?

Next read recommendations