Next upHack for Humanity: San Francisco (powered by Google Gemini)
News

Cisco Talos report finds attackers weaponizing Claude Code, Codex and other AI agents

Cisco Talos analyzed leaked AI chat logs showing attackers coaxing coding assistants like Claude Code, Codex, Cursor and Gemini into writing malware and hunting vulnerabilities.

D
Aug 4, 2026 · 1 min read

Cisco’s Talos threat-intelligence unit published a report on August 4, 2026 showing that attackers routinely manipulate AI coding assistants — including Claude Code, Codex, Cursor and Gemini — into writing malware and hunting vulnerabilities.

The findings draw on prompt histories and logs that threat actors accidentally exposed online, offering rare direct evidence that guardrails on commercial coding tools are simple to bypass at scale. Attackers also used the assistants to build scam tools, and the Cisco Talos report frames the abuse as opportunistic rather than sophisticated.

In one case, an attacker ran an AI-assisted pipeline to scan 9,180 internet-exposed hosts, recovering source code and credentials from 54 systems, Talos said. Other exposed logs documented a distributed denial-of-service operation running on roughly 2,000 Android TVs and a cryptojacking scheme that at one point drove up to 582 connected miners.

The guardrail-evasion techniques were mundane, according to the report: attackers made unverified claims of ownership or capture-the-flag authorization, split a single malicious task across separate sessions so no one prompt looked harmful, and conditioned the model with a cover persona. “Most of the time it was a simple I’m allowed to do this, and the model complied,” a Talos researcher said.

The report reflects a snapshot of artifacts attackers left exposed, not a comprehensive measure of AI-assisted crime, and Talos did not quantify how many of the operations succeeded end to end. It also does not show the model vendors failing a specific security test so much as attackers talking their way past general-purpose safety filters.

Still, the logs give defenders an unusually concrete look at how coding agents are being turned into offensive tooling, and they land as vendors race to add stronger misuse detection to assistants that now write and run code on a user’s behalf.

More news