AI & Data Engineering
For Executives
The Agent Did Exactly What the Attacker Told It To
Recently, an attacker filed a support ticket on a Supabase-backed application. The ticket contained hidden instructions directing a Cursor IDE agent — connected to the database via MCP and running with the service_role key — to read a private creden…