Tenet Security disclosed Agentjacking, a novel attack that tricks AI coding agents into running malicious code using nothing but a fake error report.
Here is how it works. Attackers craft error messages in Sentry, the error-tracking tool that every developer uses. These messages look legitimate. Agents like Claude Code, Cursor, and OpenAI Codex read the error and interpret it as debugging guidance. The agent executes code embedded in the fake report.
No malware. No stolen credentials. Just a prompt injection disguised as a bug report. And because agents trust error logs as reliable data, they comply.
During validation that ended June 17, researchers found 2,388 organizations with exposed Sentry DSNs. That is 2,388 open doors.
Sentry declined to implement a root-cause fix, saying the attack was not defensible at the platform level. That is the core insight here. AI agents cannot enforce trust boundaries between the data they retrieve and the commands they execute. The agent sees the error log and the code suggestion as a single instruction.
This is not a Sentry bug. This is an agent design problem. Expect more attacks like this.
Book your free AI clarity call, NOW!
https://buff.ly/TpWy277
Sources:
https://thehackernews.com/2026/06/agentjacking-attack-tricks-ai-coding.html
https://www.infosecurity-magazine.com/news/agentjacking-attacks-hijack-ai/
https://aviatrix.ai/threat-research-center/agentjacking-attack-ai-coding-agents-2026/
Repost this. Thanks.

