Agentjacking at DEF CON 34: AI Agent Attack Vector Exposed

Aug 9·0:00 listen·Source: forkast.news

Summary

Researchers have uncovered a new attack vector called "Agentjacking," which exploits publicly exposed Sentry Data Source Names and AI coding agents. This attack allows remote code execution on a developer's machine. Here's the thing: in controlled tests, this attack worked 85 percent of the time across over 100 organizations. It leverages the fact that Sentry's error-tracking accepts requests without authentication, and AI agents like Claude Code query Sentry for debugging. The researchers found 2,388 organizations with discoverable Sentry DSNs, including 71 in the Tranco top one million websites. Approximately 27 percent of Fortune 1000 companies were exposed through Cloudflare MCP integration alone. Attackers can steal credentials like AWS keys, GitHub tokens, and Kubernetes credentials. The attack works in six stages, ending with a malicious package exfiltrating credentials. Sentry was notified and implemented a global content filter, but declined platform-level remediation. The researchers argue this only addresses one exploit, not the underlying vulnerability. To combat this, Tenet released "agent-jackstop," hardening configurations for Cursor and Claude Code. These configurations block malicious package fetches and exfiltration, require explicit approval for commands, and treat tool output as untrusted. The bottom line: this vulnerability highlights a significant security risk for developers using AI coding agents and exposed Sentry DSNs.

Read the full article on forkast.news

This is an AI-generated audio summary. Always check the original source for complete reporting.

Share
Keep Listening