Sources
Agentjacking: Poisoned Sentry Errors Hijack Claude Code, Cursor, and Codex via MCP
Tenet Security and the Cloud Security Alliance disclosed 'Agentjacking,' an attack that injects malicious instructions into Sentry error events using only a public, write-only DSN — which MCP-connected coding agents then retrieve and execute with the developer's own system privileges. Controlled tests hit an ~85% success rate across 100+ orgs, and the chain bypasses EDR, WAF, IAM, and firewalls because every step is technically authorized. Sentry declined a root-cause fix, calling the class 'not defensible' at the platform level — anyone wiring error-tracking MCP servers into an agent should treat ingested events as untrusted input.
↳ Follow the thread