// Alert

Cloudflare threat report

Security researchers disclosed 'GhostJacking,' a novel attack class exploiting Cloudflare's WAF logs to manipulate AI agents. Attackers inject malicious instructions into blocked-request logs that agents misinterpret as operational guidance. Testing showed 9 of 10 successful attempts to convince agents to alter DNS settings under Cloudflare-recommended configurations. The attack leverages legitimate agent permissions and approved tools, bypassing traditional endpoint and WAF detection.

// Get alerts for Cloudflare