Our research on agentjacking, as featured in Dark Reading, The Hacker News, Infosecurity Magazine, SecurityWeek, VentureBeat, and more.
A single fake bug report hijacked a $250 billion company’s AI coding agent. No malware, no exploit. Every security control it passed stayed silent.
We found the attack and confirmed it in the wild across 2,388 organizations, including 71 of the top 1 million sites, with an 85% success rate. It worked against Cursor, Claude Code, and Codex, even inside network-disabled sandboxes. This is the full walkthrough, and where the defense actually has to live.
Inside the recording:
- How one poisoned log turns a routine triage request into remote code execution
- The blast radius, and why not one security control fires
- The sandbox and container bypasses that still worked
- Defenses that hold, including JackStop, the open-source hardening tool
Presenters:
- Ron Bobrov, Founding Researcher, Tenet Security. AI security and vulnerability research, DEFCON speaker.
- Nevo Poran, Co-Founder & CTO, Tenet Security. DEFCON speaker.
- Barak Sternberg, Co-Founder & CEO, Tenet Security. 3x DEFCON speaker.