Researchers at security firm Tenet demonstrated a technique called ‘GhostJacking’ at DEF CON 34, in which an attacker plants malicious instructions inside the security and observability logs an AI coding agent reads when a developer asks it to investigate an incident. The indirect prompt injection let attackers hijack domains on Cloudflare, execute code and steal credentials on Datadog, and compromise an AI agent on Sentry to vouch for them to other systems. In live testing on Cloudflare’s own recommended setup, the technique succeeded 9 out of 10 times against the Claude Code agent. Tenet also disclosed a related sandbox-escape flaw in Anthropic’s Claude Desktop that could have let agent-collected data leave a restricted sandbox; Anthropic confirmed and patched it before the DEF CON presentation.