News confirmed medium confidence

"Agentjacking": exposed Sentry DSNs let attackers drive coding agents (Tenet Security)

Tenet Security documented "Agentjacking": attackers inject malicious instructions into Sentry error events using only a public, write-only Sentry DSN (discoverable in browser JS/GitHub); when a Sentry MCP server returns the poisoned event t

On 2026-07-02, the verified AI news record added a significant safety, evals & benchmarks development: Tenet Security documented "Agentjacking": attackers inject malicious instructions into Sentry error events using only a public, write-only Sentry DSN (discoverable in browser JS/GitHub); when a Sentry MCP server returns the poisoned event to a coding agent (Claude Code, Cursor, Codex in tests), it renders like Sentry's own system template and the agent executes attacker commands with developer privileges. Tenet found 2,388 exposed organizations using only public APIs, spanning Fortune 100 to indie developers. The whole chain stays inside authorized behavior.

Context

Tenet Security documented "Agentjacking": attackers inject malicious instructions into Sentry error events using only a public, write-only Sentry DSN (discoverable in browser JS/GitHub); when a Sentry MCP server returns the poisoned event to a coding agent (Claude Code, Cursor, Codex in tests), it renders like Sentry's own system template and the agent executes attacker commands with developer privileges. Tenet found 2,388 exposed organizations using only public APIs, spanning Fortune 100 to indie developers. The whole chain stays inside authorized behavior. Tenet primary write-up not directly fetched; verify before publishing vendor-specific claims.

What changed

Public DSNs enable prompt injection through error-reporting pipelines into coding agents; 2,388 orgs exposed. According to Krypteia Security Daily Threat Brief (2026-07-19, B), citing Tenet Security, Dark Reading, Cloud Security Alliance, the supporting record states: “In Tenet's testing, coding agents including Claude Code, Cursor, and Codex retrieved the poisoned events over MCP, failed to distinguish them from legitimate application errors, and executed attacker-controlled commands with the developer's own system privileges… Tenet found 2,388 exposed organizations.”.

Why it matters

Telemetry/error channels become trusted-agent attack surfaces; extends the prompt-injection threat model to MCP-connected production tooling in the same month as GitLost and the HF breach. The safety angle matters because evaluation quality, disclosure, and monitoring determine whether capability claims can be trusted.

Details

The research file records the item under “"Agentjacking": exposed Sentry DSNs let attackers drive coding agents (Tenet Security)” with source timing of Coverage Jul 2–19, 2026. The captured research confidence note is: Medium-high. Tenet primary write-up not directly fetched; verify before publishing vendor-specific claims.

Limitations and caveats

This item is based on a single authoritative source or a company-attributed claim captured in the research file; independent corroboration was not established in the research window.

Sources

Update note: Last reviewed 2026-07-22. Next checkpoint: monitor official channels and the linked source record.

Sources

Drafted with AI assistance from source briefs; reviewed for citation completeness and label accuracy.