VentureBeat
The fix for the AI agent that hijacked a company's DNS: it can propose the change, but it can't approve it

A Cloudflare firewall blocked an attacker’s prompt-injection payload, but the payload was logged verbatim and read by an AI coding agent that had pre-issued credentials. The agent interpreted the attacker’s text as a valid instruction and rewrote the company’s DNS, demonstrating the GhostJacking chain. Tenet Security recommends adding an external authorization gate so the agent can propose changes but cannot approve them, limiting autonomous high-impact modifications.