The attack that hijacked Claud... Note
VentureBeat

The attack that hijacked Claude Code came through Sentry. Datadog, PagerDuty, and Jira have the same exposure.

Agentjacking is a new security vulnerability where malicious instructions are injected into AI coding agent data streams. A single fake error report to Claude Code, for instance, allowed an attacker to execute code with developer privileges. This exploit bypasses traditional security measures like EDR, WAF, and firewalls because every step taken is authorized and appears legitimate. Tenet Security achieved an 85% success rate in controlled tests, highlighting the systemic nature of the MCP vulnerability class. Organizations with publicly exposed Sentry credentials are at particular risk, with nearly 2,400 identified. The core problem stems from AI agents being trusted with high privileges without adequate runtime security or controls parity with human users. Surveys consistently show that enterprises do not apply the same security standards to AI agents as they do to humans. A significant gap exists between executive perceptions of AI agent policy clarity and that of frontline workers. Many organizations cannot confirm if their AI agents have exceeded their defined scope. The inability to distinguish between human and agent actions in telemetry is a critical blind spot. To address this, organizations must conduct agent inventories, ensure controls parity, audit for scope drift, close governance perception gaps, and demand breach detection certainty. Mandating agent-specific runtime detection is crucial for identifying and isolating malicious agent activity.
CdXz5zHNQW_rdhz5Gia35.png