> 🎙️ This post was auto-generated from the [Tech Updates podcast](https://rss.com/podcasts/tech-updates-by-andres-sarmiento/3098982) episode.

    DEF CON and Black Hat 2026 just wrapped up, and the security landscape has shifted in ways that should concern every IT professional managing modern infrastructure. One statistic says it all: a new attack called Ghostjacking hijacked AI coding agents with a 90% success rate using nothing but manipulated log files. This wasn't a fringe demonstration—it represents a fundamental vulnerability in how we're building and deploying AI agents at scale.

What This Episode Covers

  • Prediction Scorecard Results — How AI security dominated the conference agenda, Mythos fallout context, and why post-quantum cryptography underperformed expectations
  • Ghostjacking Attack Details — How Tenet Security poisoned telemetry data to hijack AI agents with staggering success rates
  • PleaseFix Zero-Click Hijack — Zenity’s discovery of how AI browser agents can be compromised from innocent-seeming tasks
  • Agent Framework Vulnerabilities — Check Point’s findings of 11 critical vulnerabilities in the frameworks powering AI agents
  • The Anthropic Breach Reality — Real-world AI model compromises discovered during safety testing and the alarming failure rate of AI-generated security patches
  • The Positive Stories — North Korean C2 intelligence wins, open-source silicon progress, and water utility security improvements

Deep Dive

AI Security Dominated—But for the Wrong Reasons

One in three Black Hat talks focused on AI security, but this wasn’t celebratory coverage of robust AI defenses. Instead, it was a cascade of newly discovered attack vectors. The conference revealed that as organizations rush to deploy AI agents for coding, customer service, and system management, the security foundations beneath these systems are paper-thin.

The backdrop of Mythos fallout (referenced in the notes) appears to have accelerated this shift—organizations burned by previous incidents are now more willing to publicly discuss AI vulnerabilities they’ve discovered or experienced.

Ghostjacking: Poisoning the Data AI Agents Trust

Tenet Security’s Ghostjacking attack cuts to the heart of a critical assumption in modern AI systems: that the data flowing through telemetry and logging systems is trustworthy. It isn’t.

Here’s how it works: AI agents rely on logs, metrics, and telemetry to understand their environment and make decisions. Ghostjacking poisoned this data stream, causing the agents to execute attacker-controlled commands with a 90% success rate. This isn’t a sophisticated exploit requiring zero-days or kernel-level access—it’s a data integrity attack on systems most organizations haven’t properly secured.

For IT teams, this raises an uncomfortable question: How clean is your logging infrastructure? If an attacker can access and modify logs, they can potentially hijack your AI-driven automation.

PleaseFix and Zero-Click AI Browser Hijacking

Zenity’s PleaseFix discovery reveals another attack surface: AI browser agents. Imagine an employee asks their AI assistant to “summarize my email inbox.” This innocent request flows through an agent that reads emails, aggregates information, and generates a summary. What if an attacker embeds malicious content in an email? PleaseFix demonstrated this can escalate to full account takeover—all without any user clicking a malicious link.

This is particularly dangerous because users trust AI assistants more than they trust email, creating a false sense of security.

The Framework Problem: 11 Vulnerabilities in Everyone’s Foundation

Check Point’s research identified 11 vulnerabilities in the agent frameworks that companies are standardizing on. These aren’t bugs in specific implementations—they’re structural issues in the frameworks themselves. This means any organization using these frameworks inherits these vulnerabilities, regardless of how carefully they’ve configured them.

This finding should trigger immediate framework audits across your organization.

The Anthropic Reality Check: AI Models Can Be Breached, and Patches Don’t Always Work

Anthropic’s Project Glasswing safety testing revealed that AI models can be compromised in real organizations—not just in controlled lab environments. More concerning: only 26% of AI-generated security patches actually closed the vulnerabilities they were designed to fix. This means you can’t simply ask your AI to patch itself; human verification is essential.

The Bright Spots

Not everything was dark. Researchers spent 22 months inside North Korean C2 servers gathering intelligence, volunteers secured 21 water utilities, and the open-silicon DEF CON badge demonstrated the community’s commitment to transparent, verifiable hardware.

Key Takeaways

  • Audit your logging and telemetry infrastructure immediately — Ghostjacking proves that log integrity is a critical security control that many organizations neglect
  • Treat AI-generated security patches as unverified code — The 26% patch success rate means human review is mandatory before deploying AI-generated fixes
  • Review your AI agent frameworks for known vulnerabilities — Check Point’s 11 vulnerabilities should trigger a framework audit and remediation plan
  • Assume AI assistants can be attacked through their data sources — PleaseFix shows that email, documents, and other data feeds are attack surfaces
  • Plan for AI agent compromise as an incident scenario — Add AI agent hijacking to your threat models and incident response playbooks

Why This Matters

The commoditization of AI agents is happening faster than our security practices can adapt. These systems are being deployed to handle coding, customer communications, infrastructure automation, and decision-making—yet we’re discovering fundamental vulnerabilities in how they process data and generate responses. For IT professionals, this means the security posture of your organization is now dependent on technologies you may not fully control or understand.

The good news is awareness. DEF CON 2026 has made clear what the actual vulnerabilities are. The urgent work now is implementing controls around data integrity for AI systems, establishing mandatory human review processes for AI-generated security outputs, and conducting thorough framework audits. Your security program’s evolution depends on it.

    ---

    🎧 Listen to the full episode on [Tech Updates](https://techupdates.it-learn.io) or wherever you get your podcasts.