Cisco's Talos threat intelligence group examined AI prompt histories and coding sessions that criminals accidentally left exposed online, taken from machines running Claude Code, Codex, Cursor and Gemini. The logs show attackers writing malware, hunting software flaws and building scam chatbots, often after bypassing safety filters by simply claiming to be authorised penetration testers. Some appeared to be using stolen corporate AI accounts and API keys rather than paying for their own usage.
What changed
Researchers had mostly indirect evidence of how criminals use commercial AI coding assistants.
What it unlocks
Security teams can base internal monitoring and deception defences on documented attacker prompt patterns rather than assumptions about model safety filters.
- 9,180 internet-exposed hosts scanned
- credentials and source code taken from 54 systems
- axios.com2026-08-04