GhostJacking highlights AI-agent risks in developer and cloud environments

A new attack technique called GhostJacking can use poisoned logs or alerts to manipulate AI agents into running arbitrary code on a developer’s machine. Tenet Security said the method expands on Agentjacking and can lead from an apparently routine piece of operational data to privilege escalation, enterprise cloud pivots, data exfiltration and persistence.
The finding was one of several security updates in the latest ThreatsDay bulletin, alongside a pre-trust code-execution flaw in Cursor’s CLI coding agent, a blockchain-backed ClickFix campaign and reports of malicious AI-agent skills. Together, the cases show how trusted developer tools, ordinary access paths and unattended settings can become security exposure points.
How GhostJacking targets AI agents
GhostJacking works by placing attacker-controlled content in data an AI agent is expected to inspect, such as a log entry or alert. The agent may then interpret the malicious content as an instruction and act on it. Tenet Security said an attack can make an agent execute code, raise privileges, move into enterprise cloud infrastructure and send data to an attacker.
In the demonstration described by the researchers, data exfiltration used a sandbox escape in Anthropic’s Claude Desktop that has since been patched. The attack also established persistence by leaving a backdoor in the agent’s configuration. The central concern is that the agent can misuse permissions it already holds without needing to defeat a conventional access control.
“Companies are handing AI agents the keys to their code, their monitoring, and their infrastructure,” Tenet Security said. “An AI cannot tell a real instruction from a trap hidden in the data it reads.”
Trusted workflows are becoming attack paths
The bulletin also detailed a Cursor CLI issue that allowed a cloned repository to run commands before the user was asked whether to trust the workspace. Manifold Security said the behavior occurred when the CLI agent was started with -w and could occur outside the sandbox even when --sandbox enabled had been specified. Cursor received the disclosure on July 20, 2026, and released a patch three days later.
The affected path involved a normal tracked file, .cursor/worktrees.json, delivered through an ordinary Git clone. Manifold Security said a malicious repository could read SSH material, take cloud credentials from the environment, open a reverse shell or write persistence before the workspace-trust dialog appeared.
A separate CyberProof report described malicious skills or extensions installed from public marketplaces. In one example, a package disguised as a business approval workflow enumerated browser processes and decrypted stored credentials. Because the AI coding agent ran in auto-approve mode, the activity executed silently twice in 15 minutes without user authorization prompts.
Guardrails need to cover data, extensions and privileges
These incidents do not depend on a visibly malicious executable or an obvious breach of policy. In GhostJacking, the harmful instruction is embedded in data the agent is allowed to read. In the Cursor case, the payload is delivered through a normal repository file. In the malicious-skills case, the execution mechanism is an extension operating with permissions granted for convenience.
The practical business implication is to treat AI agents as privileged components: restrict their access to code, credentials and cloud environments; review extensions and marketplace packages; avoid unattended or auto-approve execution where possible; and validate untrusted logs, alerts and repository content before allowing an agent to act on them.

