
GhostJacking: New AI Security Flaw Exploits Identity Governance Gaps
CybersecurityAI SecurityIdentity ManagementVulnerabilities
New research reveals a technique called 'GhostJacking,' which exploits identity governance gaps in AI agents by manipulating security alerts and blocked events to hijack their operations. The attack method targets weaknesses in how AI systems process and respond to security-related notifications, potentially allowing unauthorized control. No specific CVEs, dates, or affected vendors were disclosed in the findings. The impact includes the ability for attackers to bypass authentication mechanisms and execute malicious actions through compromised AI agents. The research highlights systemic flaws in identity verification and governance frameworks for AI-driven systems.