techjacksolutions.com • 22m
GhostJacking: Indirect Prompt Injection via Security Log Poisoning
GhostJacking is a novel attack class that leverages "Log Poisoning" to achieve indirect prompt injection against autonomous AI agents integrated into security orchestration, automation, and response (SOAR) pipelines. By intentionally triggering blocked security events—such as those flagged by a WAF or Firewall—attackers embed malicious instructions within the resulting telemetry logs. When an AI agent ingests these poisoned logs for analysis or incident response, it interprets the payload as a legitimate directive, bypassing perimeter defenses to execute unauthorized administrative actions or hijack agentic workflows. This mechanism effectively transforms security monitoring tools into delivery vectors for agent hijacking.