Tenet Security's DEF CON August 2026 research expands Agentjacking to Cloudflare, Datadog, and Sentry — 90% success rate, 15,000+ organisations exposed, DNS hijacking via AI coding agent manipulation, zero traditional exploitation required.
Tenet Security's DEF CON August 2026 research expands Agentjacking to Cloudflare, Datadog, and Sentry — 90% success rate, 15,000+ organisations exposed, DNS hijacking via AI coding agent manipulation, zero traditional exploitation required.
Varonis disclosed at DEF CON 34 that Atlassian Rovo's URL parameter pre-fills the AI agent with attacker-controlled prompts, enabling a one-click attack that directs Rovo's ResearchAgent to exfiltrate Jira, Confluence, Slack, and M365 data to an attacker URL.
Johann Rehberger's DEF CON Singapore research demonstrates how indirect prompt injection chains into Microsoft Copilot's memory feature to plant a persistent backdoor — one that survives across every future session, not just the compromised one.