How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

The attack that hijacked Claude Code came through Sentry. Datadog, PagerDuty, and Jira have the same exposure.

calendar_today June 29, 2026 person louiswcolumbus@gmail.com (Louis Columbus) domain venturebeat

A single fake error report hijacked Claude Code in controlled testing — the agent ran the attacker’s code with the developer’s full privileges, and not one alert fired. EDR, WAF, IAM, and the firewall all missed it completely. Tenet Security’s June agentjacking disclosure describes a single crafted Sentry error event — sent through a public credential that requires no breach and no authentication — that injected attacker instructions into error data that Claude Code, Cursor, and Codex then executed as trusted diagnostic output.

open_in_new Read original post