The Nigeria Computer Emergency Response Team (ngCERT) issued an advisory on October 6, 2026, formalizing Ghostjacking as a government-level threat. This marks a shift from academic curiosity to institutional recognition of the risks inherent in autonomous systems. The advisory codifies the threat landscape previously detailed by Tenet Security researchers Barak Sternberg, Nevo Poran, and Ron Bobrov during their DEF CON 34 presentation on August 9, 2026.
Ghostjacking exploits the Model Context Protocol (MCP) and its reliance on implicit trust. The attack vector functions because AI agents are designed to treat external data as instructions. When integrated with platforms like Cloudflare, Datadog, or Sentry, agents often process retrieved data as trusted input. Because the resulting actions—such as code execution or cloud credential access—fall within the agent’s authorized scope, conventional security controls like EDR, WAF, IAM, and VPNs remain silent. The agent is simply executing its programmed instructions, even when those instructions originate from a malicious injection.
Researchers have identified three primary MCP integration vectors:
- Cloudflare: Facilitates domain hijacking.
- Datadog: Enables code execution combined with cloud credential theft.
- Sentry: Functions as an insider-style agent vouching mechanism.
The scale of the vulnerability is quantifiable. CSA Labs research from June 2026 demonstrated an 85% exploitation success rate across Claude Code, Cursor, and Codex by leveraging Sentry DSN injection. By the time of the DEF CON 34 presentation in August, researchers observed a 90% success rate against Claude Code specifically when using Cloudflare’s recommended setup. Furthermore, an audit identified 2,388 organizations with injectable, publicly exposed Sentry DSNs, including 71 sites within the Tranco top-1M list. According to Tenet Security researchers, Sentry was notified of these findings on June 3, 2026, but declined to implement root-cause remediation, characterizing the issue as technically not defensible at the platform level.
Beyond these MCP integration vectors, researchers identified a separate vulnerability in the Claude Desktop egress sandbox. This zero-day involved JWT cross-reuse in the envoy egress gateway, allowing for session token reuse across containers. Anthropic patched this issue prior to the DEF CON 34 presentation, and no CVE was issued. This incident highlights that while MCP-based attacks are the primary focus of the Ghostjacking advisory, the underlying infrastructure of desktop-based AI agents remains a complex surface for potential privilege escalation.
For organizations deploying AI agents, the immediate challenge is the trust-through-defaults pattern inherent in monitoring and integration layers. Because detection tools are largely ineffective against actions that appear legitimate to the system, prevention must occur at the configuration level. Tenet Security has released agent-jackstop, an open-source tool providing hardening configurations for Cursor and Claude Code. It is critical to note that this is not a detection tool; it is a preventative measure intended to reduce the blast radius of a successful injection by restricting what an agent can do by default.
This advisory serves as a follow-up to our initial coverage of Agentjacking. The formalization of Ghostjacking by ngCERT underscores the transition toward a structured understanding of how AI agents can be subverted without triggering traditional security alerts. This development aligns with our previous reporting on ClawSecure MCP risks, the complexities of MCP OAuth implementations, and the broader Agent Identity Layer risks. The reliance on authorized actions means that until the industry moves away from implicit trust in MCP integrations, the burden of security rests on granular, restrictive configuration rather than reactive monitoring.
