Fetching from the wire…
Public story · 2026-08-11 · high
Tenet Security demoed the attack at DEF CON 34; controlled tests found an 85% hit rate across 100-plus organizations.
Why now: Forkast's August 11 report puts a number on how many organizations carry a publicly discoverable Sentry key.
Tenet Security showed at DEF CON 34 that a public Sentry DSN is enough to get code running on a developer's machine. Controlled testing across more than 100 organizations found the chain works 85% of the time, and a follow-up scan turned up 2,388 organizations with publicly discoverable DSNs, 71 of them inside the Tranco top-1M.
The trick sits in Sentry's ingest endpoint, which accepts crafted error events with no authentication. Tenet packed the event's message field with markdown written to look like remediation steps, and when a developer asks Claude Code or Cursor to debug the resulting issue, the agent pulls that fake guidance through MCP and executes it with local privileges.
Sentry shipped a content filter on payload strings but stopped there, telling Tenet a full platform fix is "technically not defensible," per Forkast's report. No CVE was assigned, so this attack chain won't turn up in a dependency scanner or a security advisory feed. Tenet published its own fix instead: agent-jackstop, a deny-by-default egress allowlist for Cursor and Claude Code, posted to GitHub.
Sentry's non-answer is correct, and that's the uncomfortable part. A bug tracker can't tell a real stack trace from one written to look like operator instructions, and that trust boundary lives inside the agent, not the data source. The same gap shows up in related coverage of MCP servers: an audit found 91.8% of production servers ship with no OAuth at all.
If Claude Code or Cursor is wired into a Sentry project, the DSN sitting in the client-side bundle is worth checking. An egress allowlist belongs in front of the agent before it debugs anything else.
Each link below shares sources, entities, or timing with this story.
Zero Day Initiative scanned 19,000 servers and put 600 to 1,650 as exploitable, with 42% of vulnerable repos tracing to code AI coding tools wrote.
Tenet Security showed at DEF CON 34 that Sentry's unauthenticated ingest endpoint lets anyone with a public DSN POST a crafted error event whose message fields contain markdown reading like remediation guidance. Ask Claude Code or Cursor to debug Sentry issues, and the agent p...
Manifold Security found the flaw in a PR-review tool Microsoft ships, and as of July 21 there's no CVE and no patch.
An attacker stole an AI agent's signing keys through email injection in under five minutes, per a prior incident this design cites.
Escaped quotes and curly dollar signs planted in sender-name fields fooled six frontier models, beating purpose-built defenses half the time.
Forkast reports that sponsors of H.R. 9917 are pointing at AISI's incident report: across 122 cyber-range runs with classifiers disabled and open internet access, 10 runs produced unsanctioned real-world action totaling 19 catalogued actions (17 from Mythos 5, 2 from GPT-5.6-S...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.