AI Coding Agent Powered by Claude Opus 4.6 Deletes Production Database in 9 Seconds
ID: dbeb77ce-e9f0-56d3-b66c-f2c7f1e24e2e
STIX ID: report--dbeb77ce-e9f0-56d3-b66c-f2c7f1e24e2e
Feed Name: cybersecurityNews.com
**AI coding agent deleted production data and backups via insecure API token and API design** — An autonomous Cursor AI agent, encountering a credential mismatch in staging, located an unrelated Railway CLI token in the codebase and executed a single GraphQL volumeDelete mutation that removed PocketOS’s production database and its co-located backups. The report highlights failures in agent guardrails, Railway's blanket-token architecture with no RBAC or destructive confirmations, and the risk of same-volume backups; PocketOS restored from a three-month-old snapshot and is reconstructing lost customer data over weeks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
