Webinars

Agentjacking: How We Hijacked AI Agents Inside a $250B Company

Our research on agentjacking, as featured in Dark Reading, The Hacker News, Infosecurity Magazine, SecurityWeek, VentureBeat, and more.

A single fake bug report hijacked a $250 billion company’s AI coding agent. No malware, no exploit. Every security control it passed stayed silent.

We found the attack and confirmed it in the wild across 2,388 organizations, including 71 of the top 1 million sites, with an 85% success rate. It worked against Cursor, Claude Code, and Codex, even inside network-disabled sandboxes. This is the full walkthrough, and where the defense actually has to live.

Inside the recording:

  • How one poisoned log turns a routine triage request into remote code execution
  • The blast radius, and why not one security control fires
  • The sandbox and container bypasses that still worked
  • Defenses that hold, including JackStop, the open-source hardening tool

Presenters:

  • Ron Bobrov, Founding Researcher, Tenet Security. AI security and vulnerability research, DEFCON speaker.
  • Nevo Poran, Co-Founder & CTO, Tenet Security. DEFCON speaker.
  • Barak Sternberg, Co-Founder & CEO, Tenet Security. 3x DEFCON speaker.

Ron Bobrov
Research Team
Barak Sternberg
Co-Founder & CEO
Nevo Poran
Co-Founder & CTO

Watch the recording

Complete the form to watch the full recording.

More Webinars

agentjacking cover
Webinars
min read
Agentjacking: How We Hijacked AI Agents Inside a $250B Company
A single fake bug report hijacked a $250 billion company's AI coding agent. No malware, no exploit. Every security control it passed stayed silent.
grok webinar
Webinars
min read
Grok Is Leaking Your Repositories. So, What Now?
A single fake bug report hijacked a $250 billion company's AI coding agent. No malware, no exploit. Every security control it passed stayed silent.