{"id":1288,"date":"2026-06-12T12:12:55","date_gmt":"2026-06-12T12:12:55","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1288"},"modified":"2026-06-12T12:12:55","modified_gmt":"2026-06-12T12:12:55","slug":"agentjacking-attack-tricks-ai-coding-agents-into-running-malicious-code","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1288","title":{"rendered":"Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 12, 2026<\/span><\/span><span class=\"p-tags\">Artificial Intelligence \/ Vulnerability<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhs-B-d2AZdbTGExalcZiBwa9fNa999-EQ1GrAeytHP6tpnC3WmKL4IcKV5voUs-MRq5WGVwwf2NFPyJxdJUPlgzBL8huaGFqRbXgR_qPOSh-5Ef2oZz8E2H38ZMjVipV7XyXpefY2PgDlWomgJ4RW6YJ4Z3tYMGRQh2z8xwpvOa9_LQWHT706ZCvKpaBxP\/s1700-e365\/Agentjacking.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have described what they say is a new class of attack that can trick artificial intelligence (AI) coding agents into running arbitrary code on developer machines.<\/p>\n<p>Called <b>Agentjacking<\/b> by Tenet Security, the attack can be triggered by means of a fake error report crafted using Sentry, an open-source error-tracking and performance-monitoring platform.<\/p>\n<p>\u00abThe attack exploits a critical architectural flaw at the intersection of Sentry&#8217;s event ingestion (which accepts arbitrary payloads from anyone with the DSN) and the Sentry MCP server (which returns this data to AI agents as trusted system output),\u00bb security researchers Ron Bobrov, Barak Sternberg, and Nevo Poran <a href=\"https:\/\/tenetsecurity.ai\/blog\/agentjacking-coding-agents-with-fake-sentry-errors\/\">said<\/a>.<\/p>\n<p>The idea is to inject crafted input into Sentry error events, which are then interpreted by coding agents like Claude Code and Cursor as legitimate diagnostic resolution steps and run attacker-controlled code.<\/p>\n<p>A successful attack of this kind can expose sensitive data, including environment variables, Git credentials, private repository URLs, and developer identities, without having to rely on methods like phishing or prior server compromise.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The problem is rooted in the implicit trust associated with connecting to external services using Model Context Protocol (MCP). Because an AI agent is unable to distinguish between an error event generated by a real application crash or injected by an attacker, it creates a pathway to arbitrary code execution when the agent processes the response.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The attack chain devised by Tenet is as follows &#8211;<\/p>\n<ul>\n<li>An attacker finds a target&#8217;s Sentry Data Source Name (<a href=\"https:\/\/docs.sentry.io\/concepts\/key-terms\/dsn-explainer\/\">DSN<\/a>), a public, write-only credential that&#8217;s embedded in websites.<\/li>\n<li>The attacker sends a malicious error event to Sentry&#8217;s ingest endpoint via a POST request using the DSN.<\/li>\n<li>The injected event contains \u00abcarefully formatted markdown\u00bb in the message field and context key names. When the Sentry MCP server returns this event to an AI agent, it is rendered as structured content visually identical to the Sentry&#8217;s system template.<\/li>\n<li>When a developer asks their AI coding agent to \u00abfix unresolved Sentry issues\u00bb (or a similar prompt), the agent queries Sentry via MCP and receives the malicious event.<\/li>\n<li>The agent executes malicious code, which runs with the developer&#8217;s full privileges.<\/li>\n<\/ul>\n<p><iframe loading=\"lazy\" title=\"Tenet uncovers &quot;Agentjacking&quot; Attacks Validated across 100+ enterprises\" width=\"500\" height=\"375\" src=\"https:\/\/www.youtube.com\/embed\/QSfdEQ0PE4E?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<p>\u00abThe attacker never touches the victim&#8217;s infrastructure,\u00bb the researchers explained. \u00abThe malicious instruction arrives disguised as a legitimate &#8216;Resolution&#8217; inside an ordinary error. When a developer asks their AI agent to fix the Sentry issue, the agent reads the attacker&#8217;s command as trusted guidance and runs it &#8211; with the developer&#8217;s own privileges, on the developer&#8217;s own machine.\u00bb<\/p>\n<p>Agentjacking stands out because it targets the AI agent a developer trusts and uses a Sentry DSN as a starting point. In addition, the markdown injection is rendered such that the agent cannot distinguish it from legitimate Sentry guidance.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The AI cybersecurity company said it found at least 2,388 organizations exposed with valid injectable DSNs, and that it tested the attack in a controlled manner against over 100 organizations, achieving an 85% exploitation success rate against injected errors across some of the most widely used AI coding assistants.<\/p>\n<p>Sentry, for its part, has acknowledged the issue, but opted not to fix it, stating it&#8217;s \u00abtechnically not defensible.\u00bb However, the company is said to have activated a global content filter that blocks a \u00abspecific payload string.\u00bb<\/p>\n<p>\u00abAs enterprises race to deploy AI coding agents, this research proves the agents themselves are now the attack surface &#8211; turned against the developers who trust them, using nothing but data those organizations publish about themselves,\u00bb Tenet said. \u00abThe attack bypasses EDR, WAF, IAM, VPN, Cloudflare, and firewalls &#8211; because there is nothing malicious to detect. Every action in the chain is authorized.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 12, 2026Artificial Intelligence \/ Vulnerability Cybersecurity researchers have described what they say is a new class of attack that can trick artificial intelligence (AI) coding agents into running&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1289,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[2024,335,220,10,2025,33,2011,1916],"class_list":["post-1288","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-agentjacking","tag-agents","tag-attack","tag-code","tag-coding","tag-malicious","tag-running","tag-tricks"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1288","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1288"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1288\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1289"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1288"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1288"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1288"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}