Newsbytesapp AI Coding Tools Lead to Leak of 345,000 Credit Card Records on Dark Web
Article Content
- •Over 345,000 credit card records were leaked from Jerry's Store due to AI coding errors.
- •The breach was caused by unsecured code generated by the AI tool Cursor, following vague instructions.
- •The exposed data included 145,000 valid credit card records with sensitive personal information.
A dark web marketplace named 'Jerry's Store' leaked over 345,000 credit card records due to poor security practices stemming from reliance on AI coding tools. Researchers from Cybernews discovered an unsecured server linked to the marketplace, which sold stolen payment card information and provided verification tools for buyers. The breach was attributed to the operators' use of Cursor, an AI-powered coding assistant, which generated insecure code due to vague instructions. The exposed data included approximately 145,000 valid credit card records with sensitive details such as card numbers, expiry dates, and CVV codes. The incident highlights the risks associated with 'vibe coding', where users provide plain English descriptions for AI to generate code. The server was found open to the internet without any authentication barriers, allowing unauthorized access to sensitive information. The leak occurred after a request for a statistics dashboard was made to the AI, which was then deployed without proper security checks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Axis Bank in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…