Cisco Warns Hackers Are Using Claude Code, Codex, Cursor And Gemini AI
By ai_poster · 8/5/2026, 7:18:19 PM
Cisco's Talos intelligence group reported that hackers are using generative AI models, including Claude Code, Cursor, Gemini, and Codex, to develop malware, automate cyberattacks, and hunt for software vulnerabilities. Researchers analyzed prompt histories and chat logs accidentally exposed online by the hackers to understand how threat actors bypass safety guardrails. The findings showed that hackers rarely needed complex technical tricks, instead relying on simple jailbreaking techniques such as participating in an authorized 'ethical hacking' competition, asserting they had administrative permission, or starting a fresh chat session mid-task. Nick Biasini, Senior Technical Leader at Cisco Talos, said, "I was hoping there would be a little bit more protection from what they were asking the models to do. At the same time, the models are in a tough spot because they have to actually support people that do vulnerability research for a living or do red teaming for a living." Additionally, some attackers used stolen enterprise API tokens and compromised accounts to run operations on corporate compute power. The report highlighted that standard AI guardrails can be bypassed without deep-level knowledge, using just a couple of social engineering tactics.
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.