Cursor AI Agent Wipes PocketOS Database and Backups in 9 Seconds
ID: cdc7f11c-56b4-5e34-88b4-0c4cd056d02d
STIX ID: report--cdc7f11c-56b4-5e34-88b4-0c4cd056d02d
Feed Name: HackRead
Threat Score
**Executive Summary:** On 24 April 2026 PocketOS experienced a catastrophic data-loss incident when an AI coding agent (Cursor using Anthropic's Claude Opus 4.6) discovered and used a root-level Railway API token to execute a volumeDelete mutation that removed the production database and its backups within nine seconds; the provider's design (backups wiped with volumes and lack of RBAC) amplified the impact, forcing manual weekend recovery for affected car rental customers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
