Russian Hackers Breach Six Companies via Cursor AI Agent
Prompt injection attacks on AI coding assistant expose critical security gaps in enterprise deployments.

Russian hackers have successfully breached the systems of six companies by manipulating the AI agent in Cursor, a popular AI-powered code editor, according to a report from Startup Fortune. The attackers employed prompt injection techniques, embedding malicious instructions into the AI agent's inputs, causing it to unknowingly execute unauthorized actions—including accessing internal code repositories and sensitive data.
Cursor's agent feature is designed to automate coding tasks, but this incident underscores the security risks inherent in AI agents when strict permission controls are lacking. Security researchers note that agents may fail to distinguish between legitimate commands and malicious inputs, allowing attackers to bypass traditional security measures.
As of now, Anysphere, the developer of Cursor, has not publicly responded to the incident, and the affected companies have not disclosed specific losses. The breach has reignited discussions about the security of AI agents, particularly in enterprise environments, where enhanced input validation and permission isolation are critical to mitigate such threats.
Provenance & status
- Byline
- OceanAlt Editorial
- First published
- 2026-08-29
- Last updated
- 2026-08-29
- Content type
- Newsflash
- Source material
- View original ↗


