// ClaudeHIGH
Researchers disclosed "GhostJacking," a new class of attacks exploiting trusted observability and security platforms to manipulate AI agents via indirect prompt injection. The technique succeeded in 9 out of 10 tests against Claude Code under Cloudflare configuration, enabling attackers to alter DNS settings, access environment variables, and steal cloud credentials. The attack chain exploits logs and alerts in platforms like Cloudflare, Datadog, and Sentry that AI agents are authorized to monitor.
// Get alerts for Claude