'Ghostjacking': How Hackers Trick AI Security Tools by Poisoning Their Own Logs
Security researchers have identified a new attack method dubbed 'Ghostjacking,' which targets AI agents used in cybersecurity and IT systems. Instead of attacking a system directly, attackers plant hidden instructions inside logs or alerts—records normally created when a suspicious request is blocked. When an AI agent later reads that log entry to analyse or respond to the incident, it can end up executing the attacker's planted instructions word for word, effectively turning a defensive tool against itself.
This technique is significant because many businesses are increasingly relying on AI-powered tools to monitor logs, triage alerts, and automate responses to security incidents. If those AI agents blindly trust the text found in logs without treating it as potentially untrusted input, attackers can manipulate them into taking harmful actions, even though the original malicious request was successfully blocked.
As more small and medium businesses adopt AI-driven security and IT automation tools, understanding how these systems process data becomes just as important as understanding traditional cyber risks. Ghostjacking is a reminder that AI systems can be manipulated not just through direct attacks, but through the very data they are designed to analyse and trust.