Ghostjacking: An 85 Percent Success Rate Against Coding Agents Lies Behind the ngCERT Advisory

Nigeria's Computer Emergency Response Team, ngCERT, has issued an official advisory that turns MCP-based agent hijacking — "Ghostjacking" — into a formally recognized threat at the national level.

Illustration: a small machine controlled by visible puppet strings vanishing out of frame, one string cut – a metaphor for hijacked coding agents.
Illustration
Gift article

Ghostjacking: An 85 Percent Success Rate Against Coding Agents Lies Behind the ngCERT Advisory

Nigeria's Computer Emergency Response Team, ngCERT, has issued an official advisory that turns MCP-based agent hijacking — "Ghostjacking" — into a formally recognized threat at the national level.

Nigeria's Computer Emergency Response Team (ngCERT) has issued an official advisory that makes MCP-based agent hijacking — "Ghostjacking" — a formally recognized threat at the national level. According to Forkast's reporting, this is the first time a government CERT has converted this type of security research into an institutional threat assessment, and it hits companies that connect coding agents to Cloudflare, Datadog and Sentry.

The News

Nigeria Computer Emergency Response Team (ngCERT) issued an advisory on 6 October 2026 that formalizes Ghostjacking as a government-level threat. The advisory codifies the threat picture previously detailed by researchers at the security company Tenet Security — Barak Sternberg, Nevo Poran and Ron Bobrov — in their presentation at DEF CON 34 on 9 August 2026, according to Forkast's reporting (Forkast).

It is worth emphasizing what is documented and what is not: the ngCERT advisory itself was not among the sources underlying this coverage, so all details about its contents, severity rating and recommendations come from Forkast's secondary account. It is also not confirmed whether ngCERT independently verified the research, or whether the team republished the DEF CON findings in advisory form.

What Ghostjacking Is, and How It Works

Ghostjacking is a form of agent hijacking that exploits the Model Context Protocol (MCP), the standard that lets AI agents connect to external services. The problem lies in the protocol's implicit trust model: when an agent is integrated with platforms like Cloudflare, Datadog or Sentry, it often treats retrieved data as trusted instructions. Because the resulting actions — such as executing code or accessing cloud credentials — fall within the agent's already-authorized scope, conventional security controls such as EDR, WAF, IAM and VPN remain silent (Forkast).

In other words: the attack looks like legitimate agent activity. No process behavior is anomalous, no network traffic breaks rules, and no user action exceeds permissions. That is precisely what makes this attack class hard to catch with existing tooling.

Three Documented Attack Vectors

Tenet Security's research points to three main vectors via MCP integrations (Forkast):

  • Cloudflare: enables domain hijacking.
  • Datadog: enables code execution combined with theft of cloud credentials.
  • Sentry: acts as an "insider" mechanism where the agent can confirm and vouch for malicious action.

The Sentry vector is particularly worth noting for enterprises, because it builds on something many organizations expose today: publicly accessible Sentry DSNs that can be injected into.

The Numbers, and Where They Come From

Several key figures are available, but all come from CSA Labs and Tenet Security, relayed via Forkast:

  • CSA Labs' research from June 2026 showed an 85 percent exploitation success rate across Claude Code, Cursor and Codex via Sentry DSN injection.
  • At DEF CON 34 in August, the researchers observed a 90 percent success rate against Claude Code specifically, when Cloudflare's recommended setup was in use.
  • An audit identified 2,388 organizations with injectable, publicly exposed Sentry DSNs, including 71 websites on the Tranco top-1M list.

These figures are thus the researchers' own measurements, not independently verified, but they provided the empirical basis for both the DEF CON presentation and now the ngCERT advisory.

The Vendors' Response, as the Researchers Present It

According to Tenet Security's researchers, Sentry was notified of the findings as early as 3 June 2026, but the company reportedly declined to fix the root cause, on the grounds that the problem is "technically not defensible" to fix at the platform level. This characterization is the researchers' rendering of Sentry's position — Sentry's own justification is not independently documented in the available source material, and should be read with that caveat.

The researchers additionally uncovered a separate zero-day problem in Claude Desktop's egress sandbox: JWT reuse in the envoy egress gateway that enabled session token reuse across containers. Anthropic reportedly patched this before DEF CON 34, and no CVE number was issued. Here too it is worth keeping things separate: this zero-day is not the same as Ghostjacking itself, and it is not documented which specific product versions were affected.

What Teams Can Do Today

Tenet Security has launched an open-source tool, agent-jackstop, which provides hardening configurations for Cursor and Claude Code. It is important to note what the tool is and is not: it is not a detection tool, but a preventative measure intended to reduce the blast radius of a successful injection by limiting what an agent can do by default (Forkast). This is the company's own claim about the tool's usefulness, not an independently verified effect.

For organizations running coding agents against Cloudflare, Datadog or Sentry, the immediate conclusions from the documented material are: publicly exposed Sentry DSNs are a real, measurable attack surface, and the standard security stack does not catch this attack class.

What Remains Open

Three questions remain unanswered in the available material. First: the ngCERT advisory text itself has not been published in the sources this coverage builds on, so its precise recommendations and severity assessment are unknown. Second: it is unclear whether ngCERT verified the research itself, or whether the advisory is a republication. Third: Sentry's own position is known only through the researchers' rendering, and has not been independently confirmed.

What is nonetheless new as of 6 October is the institutional shift itself: a national CERT has taken an attack class demonstrated at a hacker conference and made it a formal threat assessment. For companies with coding agents in production, the signal is that this is no longer just conference material, but something emergency response authorities now expect organizations to address.

AIMag.no
AIMag.no
The AIMag.no editorial team covers artificial intelligence, tools, research, and regulation.

Get the best of AI MAG in your inbox

News, analysis, and ideas at the intersection of AI and society.