Malicious attackers are using a technique called Ghostjacking to turn AI-driven security agents against the systems they are designed to protect.

This vulnerability represents a critical shift in cyber threats because it weaponizes the automation tools enterprises use for defense. By manipulating the data these agents trust, attackers can bypass traditional security perimeters without triggering standard alarms.

The Ghostjacking method involves injecting malicious instructions directly into security logs or alerts [1], [2]. Because AI agents often process these logs to identify and remediate threats, they may execute the poisoned instructions word-for-word [1], [2]. This effectively transforms the security agent into a tool for the attacker.

These attacks occur within enterprise security logs and alert systems that feed into AI-driven agents [1], [2]. The primary goal is to evade firewall controls and manipulate the AI into performing actions chosen by the attacker [1], [3]. This allows an external actor to operate with the privileges of the internal security tool.

Industry data suggests the scale of the risk is significant. Approximately 50% of Fortune 500 companies are vulnerable to the Ghostjacking technique [3].

Security professionals said the flaw stems from identity governance gaps and the tendency of AI agents to trust log data implicitly [2]. When an agent reads a poisoned log entry, it does not distinguish between a legitimate system alert and a command disguised as one. This lack of verification allows the attacker to steer the agent's behavior from the inside.

Ghostjacking involves injecting malicious instructions directly into security logs or alerts.

Ghostjacking highlights a fundamental trust paradox in AI integration: the more autonomy granted to security agents to remediate threats, the greater the potential impact of 'indirect prompt injection.' As enterprises move toward autonomous SOCs (Security Operations Centers), the focus must shift from simply monitoring logs to verifying the integrity of the data that triggers AI actions.