The Next Web Security firm Tenet Security has revealed a new attack vector—dubbed Agentjacking—that lets hackers take control of AI‑powered coding assistants without malware or stolen credentials. By posting a crafted error report to Sentry, a popular crash‑tracking service, attackers can trick agents such as Claude Code, Cursor and Codex into executing malicious commands on a developer’s machine. Tests showed an 85% success rate across more than 2,300 organizations, from Fortune‑500 firms to solo developers, exposing environment variables, cloud keys and private repository data. Sentry acknowledged the issue but offered only a limited fix, leaving the broader problem of how AI agents trust external data unresolved.
Leggi di più