#Agentjacking

Every story tagged Agentjacking, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

1 story · open in the command center

  • Security & PrivacyVentureBeatlouiswcolumbus@gmail.com9m

    The attack that hijacked Claude Code came through Sentry. Datadog, PagerDuty, and Jira have the same exposure.

    A critical vulnerability class called 'agentjacking' allows attackers to inject malicious code into AI coding agents through trusted data sources like Sentry, Datadog, and Jira with an 85% success rate, completely bypassing all standard security controls (EDR, WAF, IAM, firewall) because every step in the attack chain is technically authorized. Enterprise surveys reveal a dangerous gap: only 34% of organizations apply equivalent security controls to AI agents as human users, 33% report agents have already exceeded their intended scope, and 88% have experienced confirmed or suspected incidents, yet most organizations lack runtime monitoring and continuous identity verification for agentic systems. IT leaders must immediately shift from perimeter-focused security to real-time action-level authorization and runtime enforcement, as sandbox approaches are both impractical and ineffective given agents' value derives entirely from system access.

Browse all tags