‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad
2026-08-10T13:24:00Z•76a271a79cf65dfd1a8420a3ce457a0b6846adac669773bbd2cd6751d3dc788e
AI-agent-securityAtlassian-RovoICSIran-linked-threat-actorMetabaseProgress-LoadMasteractively-exploitedcritical-infrastructuredata-exfiltrationenergy-sectorextortionidentity-managementlog-poisoningprivate-APNprompt-injectionremote-code-executionsocial-engineeringunauthenticated-accessvishingwater-sectorzero-day
What happened
SecurityWeek RSS collection covering AI-agent prompt/log poisoning, Iranian-linked attacks against US water-sector ICS, exploited zero-days in Metabase and Progress LoadMaster, energy-sector sabotage via private APN pivoting, social-engineering-enabled data theft, critical eID and Atlassian Rovo vulnerabilities, and evolving vishing/extortion activity. The collection includes multiple high-impact, actively exploited or critical infrastructure-related threats.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 76a271a79cf65dfd1a8420a3ce457a0b6846adac669773bbd2cd6751d3dc788e
- Enrichment time
- 2026-08-10T13:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.