'GhostJacking' Exposes Identity Governance Gaps in AI Agents

New research reveals that attackers can exploit security alerts and blocked events to hijack AI agents, a technique called "GhostJacking" that exposes critical gaps in identity governance.

A new attack method called "GhostJacking" exploits identity governance gaps in AI agents, allowing attackers to manipulate and hijack them using security alerts and blocked events, according to recent research. The technique leverages how agents process security notifications, turning defensive responses into offensive vectors. This highlights critical vulnerabilities in AI agent identity management, where attackers can subvert agents by feeding them crafted alerts from blocked actions. The findings underscore the need for stronger governance frameworks to prevent such hijacking.