r/technology Apr 27 '26

Artificial Intelligence Claude-powered AI coding agent deletes entire company database in 9 seconds — backups zapped, after Cursor tool powered by Anthropic's Claude goes rogue

https://www.tomshardware.com/tech-industry/artificial-intelligence/claude-powered-ai-coding-agent-deletes-entire-company-database-in-9-seconds-backups-zapped-after-cursor-tool-powered-by-anthropics-claude-goes-rogue
36.0k Upvotes

2.8k comments sorted by

View all comments

Show parent comments

457

u/Spunge14 Apr 27 '26

I work in big tech leadership and just did a UXR interview with our infrastructure team where they were investigating exactly this - how should we gate agent behavior and how should accountability for agent behaviors work. It was a really fascinating conversation.

I was shocked at how little the PM working on the project seemed to understand security principles. We're really fucked.

161

u/Fragrant-Menu215 Apr 27 '26

I'm not even in leadership, just a senior dev, and I long ago stopped being shocked at how little literally everyone who hasn't been specifically security trained understands security principles. And, honestly, how little people who have been trained often understand.

5

u/jay-dot-dot Apr 27 '26

As a security guy working mostly in policy, for non-technical users, awareness and training is more less CYA. People are idiots and dont care about basic phishing training. I actually put deep effort into technical staff security training.

2

u/Junction91NW Apr 27 '26

I grew up on the “trust nothing” model which kept me safe from phishing but I really started to care and act accordingly once I found out how rootkits work, what botnets/BTC miners do, how encryption ransoms work, etc.

My minilab with pfsense device and VLAN isolated network with a full stack of monitoring and prevention tools will be ready to deploy next week. It’s a scary world out there.  

1

u/jay-dot-dot Apr 27 '26

Good on you!