What happened
An attacker injects malicious instructions into web server logs; the developer tasks Claude Code with reviewing Sentry/Datadog logs, and the agent executes the payload.
2026-08-10
HighPrimaryAnalysis of the GhostJacking exploit presented at DEF CON 2026, where poisoned Sentry, Datadog, or Cloudflare logs executed commands in Claude Code.
What happened
An attacker injects malicious instructions into web server logs; the developer tasks Claude Code with reviewing Sentry/Datadog logs, and the agent executes the payload.
Why it matters
Complete workstation compromise, DNS hijacking, and exfiltration of AWS/GitHub keys and session tokens.
Missing authorization check
All system command execution and host filesystem modifications must require cryptographically-signed authorization receipts.
Would PP block it?
Even if a poisoned log overrides Claude Code's system prompt and instructs it to modify system files or run shell scripts, the agent cannot execute these actions. PP's Runtime Gate intercepts all tool executions and requires a valid, cryptographically-signed receipt. Since the log payload cannot forge the human operator's private key signature, the RCE payload fail-closes.
Incident analysis
2026-08-10
Tenet Security presents GhostJacking at DEF CON 2026, demonstrating 90% exploit success against Claude Code.
2026-08-10
Tenet Security publishes a blog post detailing observability log injection vectors.
Authorization boundary
This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Runtime Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
PP's Runtime Gate intercepts all shell executions and prevents unauthorized commands regardless of log poisoning.
Related incidents and controls
Start small
This incident maps to Runtime Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.