AI News selected for Professionals and Decision Makers
AI Security And Privacy Updates

Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code

14:04 · June 12, 2026 · Hacker News AI Section

Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code

Cybersecurity researchers have described what they say is a new class of attack that can trick artificial intelligence (AI) coding agents into running arbitrary code on developer machines. Called Agentjacking by Tenet Security, the attack can be triggered by means of a fake error report crafted using Sentry, an open-source error-tracking and performance-monitoring platform. "The attack

Summary

Cybersecurity researchers at Tenet Security have identified a new attack class, termed Agentjacking, that allows adversaries to induce AI coding agents into executing arbitrary commands on developer workstations. The technique relies on Sentry, the open-source error-tracking platform, as the delivery channel. By submitting a crafted error event through a publicly known Data Source Name, an attacker can embed malicious instructions that later appear as legitimate diagnostic guidance when the agent queries the Sentry MCP server.

The attack succeeds because AI agents such as Claude Code and Cursor treat data returned from connected external services as trusted context. When a developer asks the agent to investigate or resolve a Sentry-reported issue, the model interprets the injected “Resolution” field as authoritative advice and runs the embedded commands under the developer’s own privileges. No direct access to the victim’s infrastructure is required; the malicious payload travels through the same error-reporting pathway that organizations already expose for legitimate monitoring.

Successful exploitation can surface environment variables, Git credentials, private repository locations, and developer identities. Tenet Security reported discovering at least 2,388 organizations with injectable DSNs and achieved an 85 percent success rate when testing the technique against more than 100 targets using widely deployed coding assistants. Sentry has acknowledged the underlying design tension between open event ingestion and downstream agent consumption but has declined a structural fix, citing technical constraints, and has instead deployed a narrow content filter for one known payload string.

The finding underscores how the integration of AI agents with external data sources expands the attack surface beyond conventional network defenses. Because every step in the chain appears as authorized activity initiated by the developer, existing controls such as endpoint detection or web-application firewalls offer limited visibility.

Why it matters

Directly addresses AI security risks and vulnerabilities with actionable insights for professionals defending AI coding workflows in the Netherlands and EU.

More in this beat
agentjackingagent-safetyai-agentsclaude-codecursormodel-security-controlsprompt-injectionthreat-and-vulnerability-updates
Red Hat Explains the Agentic AI Cybersecurity Risk CX Teams Can't Ignore

16:23 · July 15, 2026

Red Hat Explains the Agentic AI Cybersecurity Risk CX Teams Can't Ignore

This article is highly relevant for security and privacy professionals as it addresses the critical vulnerabilities introduced by autonomous AI agents, such as prompt injection and data leakage. The recommended mitigation strategies—sandboxing and data segmentation—are essential for Dutch enterprises to maintain GDPR compliance and secure customer data.

Relevance 85 · Audience 95

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

19:46 · June 30, 2026

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

This article is highly relevant for security and privacy professionals as it exposes a novel attack vector against AI agents that bypasses traditional security alarms. Understanding this vulnerability is crucial for Dutch enterprises to secure their AI deployments and prevent data breaches that could violate GDPR.

Relevance 90 · Audience 95

Agent-Native Immune System: Architecture, Taxonomy, and Engineering

06:00 · June 29, 2026

Agent-Native Immune System: Architecture, Taxonomy, and Engineering

This research aligns perfectly with the Dutch AI market's strategic focus on secure, ethical, and transparent AI. It provides advanced researchers with a novel, dynamic runtime defense framework necessary for deploying safe autonomous agents within strict EU regulatory environments.

Relevance 85 · Audience 95

ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories

15:20 · June 11, 2026

ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories

The article highlights emerging security vulnerabilities specific to AI, such as the phishing of AI agents and patches for AI coding assistants like Claude. Dutch security professionals must understand these attack vectors to secure enterprise AI deployments and maintain compliance with strict EU data protection regulations.

Relevance 75 · Audience 85

How we contain Claude across products

02:00 · May 25, 2026

How we contain Claude across products

Highly actionable for Product Teams and Builders: provides concrete implementation patterns, risk trade-offs, and lessons on agent security that directly apply to building safe AI products. Addresses limitations, prompt injection, and oversight fatigue with measurable outcomes.

Relevance 85 · Audience 90

Beyond permission prompts: making Claude Code more secure and autonomous

02:00 · October 20, 2025

Beyond permission prompts: making Claude Code more secure and autonomous

Provides actionable security architecture and open-source components for building safer AI coding agents, directly applicable to product teams implementing autonomous workflows. Addresses real risks like data exfiltration with concrete isolation boundaries and measurable prompt reduction. Open-sourcing enables Dutch builders to integrate similar controls into their own agents.

Relevance 78 · Audience 85

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

16:36 · August 20, 2026

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

This article highlights a critical data exfiltration vulnerability in LLMs via context injection, which is highly relevant for security professionals defending AI systems. Understanding this attack vector is essential for Dutch enterprises to ensure GDPR compliance and protect user privacy when deploying AI chatbots.

Relevance 85 · Audience 95

Phishing 3.0: The Fight Moves to Agent Versus Agent

13:30 · August 19, 2026

Phishing 3.0: The Fight Moves to Agent Versus Agent

This article is highly relevant for security professionals as it highlights the emerging threat of AI-driven phishing agents. Dutch enterprises must adapt their cybersecurity strategies to counter AI-generated attacks, making this crucial for maintaining robust organizational security.

Relevance 85 · Audience 95

Agentao: A Governed Local-First Runtime for Tool-Using LLM Agents

06:00 · August 17, 2026

Agentao: A Governed Local-First Runtime for Tool-Using LLM Agents

Agentao's focus on runtime governance, auditability, and permission-mediated execution aligns strongly with the transparency and human-oversight requirements of the EU AI Act. Dutch AI researchers and engineers can leverage this open-source architecture to build compliant, secure, and inspectable local-first AI agents.

Relevance 85 · Audience 90

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

20:17 · August 13, 2026

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

This article is highly relevant for security professionals as it details emerging attack vectors against AI agents and coding assistants, alongside new defensive strategies like Context Bombs. Understanding these threats is crucial for Dutch enterprises to secure their AI supply chains and maintain compliance with data protection standards.

Relevance 85 · Audience 95