1 post found
A new attack class called agentjacking hides malicious instructions inside Sentry error events. When you tell Claude Code or Cursor to 'fix the unresolved errors,' the agent reads the trap over MCP and runs the attacker's commands — with your privileges. 2,388 orgs were exposed, the success rate was 85%, and Sentry says it's 'technically not defensible.'