Content Quality: Well-structured News-category piece (794 words) with Overview / What We Know / What We Don't Know / Industry Response sections. Neutral, non-sensational tone despite a headline-worthy attack success rate. Technical mechanism is explained accurately without reproducing exploit payloads or step-by-step reproduction instructions.
Source Verification: All three source snapshots read in full from disk (gunzip, sha256 verified against manifest before reading): sources/2026-08/tenet-securitys-ghostjacking-attack-tricked-claude-code-into-rewriting-cloudflare-dns-records-9-times-out-of-10/source-0.html.gz (tenetsecurity.ai primary blog, sha256 c01c8e18... matched), source-1.html.gz (securityweek.com, sha256 aeb692f2... matched), source-2.html.gz (venturebeat.com, sha256 9c706489... matched). No live WebFetch was used; all verification was against the committed snapshots.
Factual Accuracy: Targeted verification per the review brief: (1) '9 times out of 10' / 'Claude Code (Sonnet 4.6)' — confirmed VERBATIM in Tenet Security's own primary blog post (source-0), which states in its Cloudflare section 'Impact: 90% success against Claude Code (Sonnet 4.6)' and in its intro '9 out of 10 times against Claude Code, on Cloudflare's own recommended setup.' Independently corroborated by SecurityWeek's direct quote of Tenet: '"It worked 9 times out of 10 against Claude Code... ," Tenet says.' This is not a secondary paraphrase — it traces to the primary source. (2) Datadog and Sentry variant attacks — correctly characterized as distinct from the primary Cloudflare/DNS finding. Tenet's own blog frames Datadog as item 2 in a numbered 'kill chain' list ('The same attack worked on a third platform: Datadog... which is how we know it's a pattern, not a Cloudflare bug') and Sentry as item 3 ('Attack that jumps from one AI Agent to another agent'/agent-to-agent lateral movement via Seer) — a materially different mechanism from the Cloudflare DNS case. The article's phrasing ('demonstrated variants of the attack against two other widely used platforms') accurately reflects this without conflating the three findings' distinct mechanics or impacts (DNS hijack vs. RCE/credential exfiltration vs. agent-to-agent trust abuse). (3) OWASP/Steve Wilson quote — verified verbatim against source-2 (VentureBeat): both sentences ('The first thing I'd do is put an authorization gate outside the model' / 'The agent can propose the exact DNS change, but it cannot grant itself the authority to make it') match the source exactly, and his title (Chief AI and Product Officer at Exabeam, OWASP Top 10 for LLM Applications co-lead) is accurately represented. Kayne McGladrey/IEEE quote also verified verbatim. FINDING: one quote-fidelity issue — the article renders a VentureBeat quote as '"Tenet Security found public evidence of the exposed setup at 48 organizations, six confirmed Fortune 500 companies."' but VentureBeat's actual text (source-2) reads 'Tenet found public evidence of the exposed setup at 48 organizations, six confirmed Fortune 500 companies' — the word 'Security' was inserted inside quote marks that claim verbatim reproduction. The underlying fact (48 organizations, 6 confirmed Fortune 500) is accurate and independently confirmed in Tenet's own blog, so this is a quote-wording error, not a fabricated fact, and sits in a subordinate body paragraph, not the headline/summary/lead. Also verified: the 15,000+ extrapolation is correctly framed in the 'What We Don't Know' section as an extrapolation, not a hard count (Tenet's blog: '15,000+ estimate extrapolates from 73 public, source-linked artifacts across 48 organizations... It reflects adoption of the vulnerable setup, not a confirmed breach'). Cloudflare/Datadog Fortune-500 percentages, the ~20% internet traffic figure, and the Sentry '4 million developers' figure all check out against the sources.
Overall Assessment: Substantively accurate, well-sourced, and neutrally written article on a legitimate, publicly disclosed DEF CON 34 security research finding. The only defect found after reading all three sources in full is a single inexact quotation of a subordinate statistic in a non-lead paragraph, which a corrections record can honestly and fully address. The automated REJECT was driven by a false-positive prompt-injection scanner match on the source's own research narrative, not a genuine integrity problem; overridden after manual verification of the exact literal excerpt per the false-positive protocol.