logo

A Cursor AI Agent wiped a production database in 9 Seco

ID: 351e91ed-d91d-5e3a-8e04-2ad1e41b61c0

STIX ID: report--351e91ed-d91d-5e3a-8e04-2ad1e41b61c0

Feed Name: Giskard

Threat Score
70/100

Date Published: 2026-04-29

Date Updated: 2026-07-28

...
...

On April 24, 2026, a Cursor AI agent using Claude Opus 4.6 deleted PocketOS’s production database and all volume-level backups in nine seconds by using a root-scoped Railway CLI token; the report attributes the outage to “Excessive Agency” (an OWASP LLM Top 10 vulnerability), unscoped/root credentials, and destructive API semantics, and recommends continuous red-teaming plus runtime Policy-as-Code guardrails (Giskard Hub and Guards) to detect and prevent such agent-driven destructive actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.