Research2026-08-04

Cisco's Talos threat intelligence group examined AI prompt histories and coding sessions that criminals accidentally left exposed online, taken from machines running Claude Code, Codex, Cursor and Gemini. The logs show attackers writing malware, hunting software flaws and building scam chatbots, often after bypassing safety filters by simply claiming to be authorised penetration testers. Some appeared to be using stolen corporate AI accounts and API keys rather than paying for their own usage.

What changed

Researchers had mostly indirect evidence of how criminals use commercial AI coding assistants.

What it unlocks

Security teams can base internal monitoring and deception defences on documented attacker prompt patterns rather than assumptions about model safety filters.

  • 9,180 internet-exposed hosts scanned
  • credentials and source code taken from 54 systems

Send this to someone who needs it

Shares the story and its sources. Nothing about you.

What does this mean for your job?

This is the story as everyone gets it. Once a week we send you the version written for your role — what changed, why it matters for the work you actually do, and one thing to try. Free while we tune it.