- What: New attack technique called Agentjacking exploits AI coding tools via fake error reports
- Impact: Developers using AI assistants like Claude Code may be at risk if they process untrusted Sentry error logs
AI/ML Agentjacking attack exploits AI coding tools with fake error reports June 18, 2026 Share By SC Staff (Adobe Stock) Agentjacking, a novel attack technique, has been demonstrated by Tenet Threat Labs, showcasing how fabricated Sentry error reports can manipulate AI coding agents into executing commands on a developer's machine. This method exploits the way AI coding assistants process untrusted error logs from Sentry, a widely used application monitoring platform, based on information published by HackRead. The Agentjacking attack bypasses the need for stolen credentials or direct network access. Attackers can identify a website's public Sentry Data Source Name (DSN) and submit a malicious error report containing Markdown injection. When an AI coding agent, such as Claude Code or Cursor, investigates this report via a Sentry MCP server, it can interpret attacker-controlled text as instructions. Tenet's proof of concept showed an AI agent executing a command to download and run a malicious npm package, demonstrating a path to remote code execution with the developer's local permissions. Over 2,388 organizations with exposed DSNs were identified, and AI assistants at more than 100 companies, including a Fortune 100 technology firm, ran Tenet's test code. This attack is difficult for traditional security tools to detect as it appears to be authorized user activity. Tenet reported the vulnerability to Sentry on June 3, 2026, leading to a content filter being added, but a broader fix remains challenging due to the fundamental issue of AI agents treating untrusted output as commands. Tenet has released a tool called Agent-JackStop to help mitigate these risks. Source: HackRead An In-Depth Guide to AI Get essential knowledge and practical strategies to use AI to better your security program. Learn More SC Staff Related AI/ML BlackFog launches AI detection for macOS SC Staff June 18, 2026 The new ADX Vision for macOS targets the increasing use of unsanctioned generative AI tools within organizations. AI/ML AWS launches Continuum security platform with AI SC Staff June 18, 2026 AWS Continuum utilizes model-agnostic AI, drawing from various frontier models to analyze structured data like infrastructure and code, as well as unstructured data such as documents and communications. AI/ML As AI enters the SOC, evidence becomes more important than ever Stephen Donnelly June 18, 2026 AI speeds investigations, but packet capture provides proof. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds