Nigeria’s CERT calls for independent authorization before AI agents receive broader production access. The agency published its GhostJacking warning on October 6.
Poisoned logs and alerts could make agents use existing privileges to follow an attacker’s instructions. The agency describes indirect prompt injection.
ngCERT recommends reducing privileges and separately validating tool calls. Another agent’s output should not automatically be trusted.
The advisory describes possible consequences, not a confirmed new attack. Named cloud services are integration examples, not verified victims.