'GhostJacking' Exposes Identity Governance Gaps in AI Agents
Researchers at Tenet Security have demonstrated a significant vulnerability in AI agents, dubbed ‘GhostJacking,’ where attackers can manipulate security alerts and logs to trick agents into executing malicious commands and stealing sensitive information. The attacks exploit the agents’ reliance on trusted data sources and their tendency to blindly follow instructions, regardless of their origin. This isn’t a bug in a specific product, but a fundamental issue with how AI agents consume and act upon data. Organizations need to drastically improve identity governance and implement stricter controls to prevent agents from being exploited, focusing on least privilege and human oversight.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
