VFF - The signal in the noise
News

Agentjacking Bypasses All Security Controls in AI Coding Agents

Read original
Share
Agentjacking Bypasses All Security Controls in AI Coding Agents

Tenet Security disclosed a vulnerability class called agentjacking that allows attackers to inject malicious instructions into error data from services like Sentry, which AI coding agents then execute with full developer privileges. Testing achieved an 85% success rate across 100-plus targets, and 2,388 organizations were found with publicly exposed Sentry credentials vulnerable to this attack. The flaw bypasses all traditional security controls because every step in the attack chain is technically authorized.

  • A single crafted Sentry error event can hijack Claude Code, Cursor, and Codex agents to execute attacker code with developer privileges
  • Tenet achieved 85% success rate in controlled testing and identified 2,388 organizations with publicly exposed Sentry credentials
  • The attack bypasses EDR, WAF, IAM, and firewalls because it uses authorized API calls and trusted data sources
  • Only 34% of organizations apply the same security controls to AI agents as to humans, according to Okta/Apprize360 survey

Agentjacking represents a new attack surface that existing security infrastructure cannot detect or prevent. Because AI agents execute commands as authorized users accessing trusted data sources, traditional perimeter and endpoint controls remain blind to the attack. This creates a systemic vulnerability across any organization running AI coding agents connected to monitoring and incident management platforms.

Organizations deploying AI coding agents face a gap between the privileges those agents hold and the security controls monitoring them. One captured Claude Code environment contained live AWS secret access keys and private repository URLs, demonstrating that agentjacking can expose production credentials and source code at scale. The Cloud Security Alliance classified this as a systemic MCP vulnerability class, signaling industry-wide risk.

  • AI coding agents require runtime security controls distinct from traditional user and endpoint security, a gap the industry has not yet addressed
  • Public DSN credentials for services like Sentry, Datadog, PagerDuty, and Jira create injection vectors that agents will trust as legitimate diagnostic output
  • Organizations must audit publicly exposed credentials and restrict what data agents can execute based on, not just who can access the data
  • The gap between agent deployment and security approval is widening, with agent estates doubling while monitoring barely moved according to Gravitee survey

Monitor for runtime security solutions designed specifically for AI agents, as CrowdStrike and others begin addressing the gap in agent-specific controls. Watch for policy changes from Sentry, Datadog, and other MCP-connected services around what data agents can access and execute. Track adoption of security controls that distinguish between developer commands and agent-initiated commands in response to external data.

Share

Subscribe to the newsletter

The latest stories and analysis, delivered to your inbox.

Free. No spam. Unsubscribe any time.

Related stories

Z.ai Releases GLM-5.3 as Cybersecurity AI Rival
TrendingModel Release

Z.ai Releases GLM-5.3 as Cybersecurity AI Rival

Chinese AI developer Z.ai released GLM-5.3, an open-source model it claims matches Anthropic's Mythos 5 in cybersecurity capabilities. The Beijing-based company, also known as Zhipu, positioned the model as a significant improvement over its predecessor GLM-5.2. The release marks another step in China's competitive push in generative AI development.

by Juro Osawa· The Information
Startup Slack Threads Become Commodity for AI Training
TrendingNews

Startup Slack Threads Become Commodity for AI Training

AI training companies like Mercor are actively acquiring internal communications and code from startups, offering payments up to $300,000 for Slack threads, GitHub records, and meeting transcripts. Warmly's CEO received four such acquisition offers within days of the company's HubSpot acquisition announcement. The practice highlights how internal startup data has become a commodity for AI model training, even as acquirers may not want the same datasets.

by Alix Coutures· The Information
OpenAI Daybreak cybersecurity models now on AWS

OpenAI Daybreak cybersecurity models now on AWS

OpenAI and AWS have integrated Daybreak cybersecurity capabilities into Amazon Bedrock, making the models available to enterprise customers. Daybreak is positioned to support security workflows through AWS's managed service for foundation models. The partnership expands access to OpenAI's cybersecurity-focused AI tools for organizations already using AWS infrastructure.

· OpenAI
AWS Embeds Security in Rival AI Models, Betting on Control Plane

AWS Embeds Security in Rival AI Models, Betting on Control Plane

AWS announced at Black Hat USA 2026 that its Continuum vulnerability platform will integrate directly into Anthropic's Claude Code and OpenAI's Codex, embedding AWS security tooling at the point where developers write code regardless of which AI model they use. The move positions AWS as a security control plane for enterprise software development and reflects an urgent industry response to frontier AI models like Claude Mythos Preview, which identified thousands of previously unknown zero-day vulnerabilities during testing. AWS also expanded its Security Hub Extended marketplace with a 10th category focused on supply chain protection, adding Chainguard and Socket as partners.

by michael.nunez@venturebeat.com (Michael Nuñez)· VentureBeat AI