---
title: "SpaceX acquires Cursor for $60B, LiteLLM critical RCE needs patching now"
url: https://daily.dev/posts/spacex-acquires-cursor-for-60b-litellm-critical-rce-needs-patching-now-3m0ryfrwk
source_url: https://daily.dev/posts/spacex-acquires-cursor-for-60b-litellm-critical-rce-needs-patching-now-3m0ryfrwk
type: freeform
source: "Agentic Digest"
published: 2026-06-17T04:18:07.728Z
updated: 2026-06-17T04:18:38.916Z
tags: ["security", "llm", "ai-coding"]
reading_time: 5
upvotes: 4
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# SpaceX acquires Cursor for $60B, LiteLLM critical RCE needs patching now

**[Agentic Digest](https://daily.dev/sources/agents_digest)** · 5 min read · 4 upvotes · 0 comments

## Summary

A packed AI developer news roundup covering four major stories: SpaceX signed a $60B all-stock deal to acquire Cursor parent Anysphere, combining GPU capacity with enterprise AI distribution. A critical CVSS 9.9 LiteLLM vulnerability chain enabling privilege escalation and RCE is in CISA's KEV catalog with a June 22 patch deadline — upgrade to v1.83.14-stable and rotate all API keys immediately. GLM-5.2 topped Design Arena at Elo 1360 while costing 82% less than Claude Opus 4.8, reinforcing a trend of challenger models closing the quality gap at a fraction of the price. Anthropic reversed a planned Agent SDK billing change on the day it was due, affecting tools like Zed and Conductor. Notable items include 15 malicious JetBrains plugins stealing AI API keys (70K installs), 1Password acquiring Apono for AI agent access governance, DeepSeek closing a $7B+ funding round, GitHub Models closing to new customers, and Kimi K2.7-Code outperforming Claude Opus 4.8 on agentic benchmarks at lower cost.

## Content

**TLDR:** SpaceX officially signed a binding agreement to acquire Cursor's parent Anysphere for $60 billion in stock, days after its IPO, framing the deal as a compute-plus-distribution play. GLM-5.2 topped Design Arena with an Elo of 1360 and is 82% cheaper than Claude Opus 4.8, making the cost gap between frontier and challenger models impossible to ignore. A critical LiteLLM vulnerability chain (CVSS 9.9) is already in CISA's KEV catalog with a June 22 deadline. Anthropic reversed a planned billing change to its Agent SDK on the day it was set to take effect, amid broader turbulence around the Fable 5 export control situation.

---

## SpaceX acquires Cursor for $60B, four days after IPO

SpaceX filed a binding all-stock agreement with the SEC to acquire Anysphere — the company behind Cursor — at a $60 billion valuation, with a $10 billion break-up fee if the deal falls through. Cursor was generating roughly $2.6 billion in ARR and had been in talks for a $2 billion funding round at a $50 billion valuation before SpaceX stepped in. The strategic logic: SpaceX has massive GPU capacity via xAI's Colossus supercomputer but no profitable AI distribution channel; Cursor brings Fortune 500 enterprise adoption. Investor Gavin Baker flagged Cursor's Composer 2.5 — already Pareto dominant after three weeks of RL on Colossus 2 — as the key variable to watch as it gets applied to larger base models. [Read more](https://app.daily.dev/feed-by-ids?id=dtKuV5kn7&id=6bTmz1odT&id=sgN0r7dAZ&id=NWElnhj6e&id=mQgwYD3Sf)

## LiteLLM critical RCE chain (CVSS 9.9) in CISA KEV, patch by June 22

A three-CVE chain in LiteLLM allows any low-privilege user to escalate to full admin and execute arbitrary code on the gateway host. A separate unauthenticated RCE (CVE-2026-42271) affecting versions 1.74.2–1.83.6 is already in CISA's Known Exploited Vulnerabilities catalog with a June 22 remediation deadline. A successful exploit exposes all provider API keys — OpenAI, Anthropic, Azure, AWS Bedrock — plus in-flight prompts and MCP OAuth tokens. Immediate actions: upgrade to v1.83.14-stable, rotate all provider API keys, audit proxy_admin accounts, and disable Custom Code Guardrails if unused. [Read more](https://app.daily.dev/posts/2Dh1T9Pl9)

## GLM-5.2 leads Design Arena at Elo 1360, priced 82% below Claude Opus 4.8

GLM-5.2 took the top spot on Design Arena with an Elo score of 1360, surpassing Claude which is listed as unavailable. At $4.40 per million output tokens versus $25 for Claude Opus 4.8 and $30 for GPT-5.5, the cost gap is hard to dismiss. A separate game-generation benchmark found OSS models like MiniMax M3 and Nemotron Ultra delivering similar quality at up to 15x lower cost than frontier models — though frontier models still hold an edge on harder tasks. The pattern is consistent: for agentic loops and execution-heavy workflows, the cheapest model that clears the quality bar is increasingly not the one from Anthropic or OpenAI. [Read more](https://app.daily.dev/feed-by-ids?id=QFEkpwa9w&id=1SRRY7pyD&id=tJ5IvDgRN)

## Anthropic reverses Agent SDK billing change on the day it was due

Anthropic paused a planned billing change to its Claude Agent SDK — which would have moved third-party tool usage from the shared monthly subscription pool to a separate credit billed at full API rates — on the very day it was set to take effect. The reversal affects tools like Zed and Conductor that rely on the SDK for agentic workflows. Anthropic says it's working on a revised approach but gave no timeline. The rollback comes alongside the ongoing Fable 5 export control situation, a proposed class action over advertised usage limits, and competitive pressure from OpenAI. [Read more](https://app.daily.dev/feed-by-ids?id=eP4dwlkTr&id=fY5QBEefu)

---

## Also notable

- **15 JetBrains plugins caught stealing AI API keys, 70,000 installs:** A coordinated malware campaign on the JetBrains Marketplace — active since October 2025, still adding plugins in June 2026 — silently exfiltrates OpenAI, DeepSeek, and SiliconFlow API keys to a hardcoded attacker-controlled server over plain HTTP; a full list of affected plugin IDs and the C2 server IP are in the disclosure. [Read more](https://app.daily.dev/posts/e0cBtEfUM)
- **1Password acquires Apono for $250–300M to govern AI agent access:** 1Password bought Israeli startup Apono to expand from password management into just-in-time, intent-based access for AI agents — revoking permissions automatically when tasks complete — putting it in direct competition with CyberArk and Wiz; SailPoint made a same-day acquisition of rival Entro for ~$200M, signaling rapid consolidation in the non-human identity security market. [Read more](https://app.daily.dev/feed-by-ids?id=zCDmZOU29&id=5ud7yC1TD)
- **DeepSeek closes $7B+ round at $52–59B valuation, founder retains control:** DeepSeek's first external funding round closed at roughly $7 billion (50 billion yuan), with founder Liang Wenfeng personally contributing 20 billion yuan to preserve control; Tencent and CATL are among the outside backers. [Read more](https://app.daily.dev/posts/m7C3t4nEk)
- **GitHub Models closed to new customers, Azure AI Foundry suggested as replacement:** GitHub is retiring its AI model playground and API service — new organizations and enterprises can no longer access it on any plan, with existing customers unaffected for now. [Read more](https://app.daily.dev/posts/tDRgBaJHi)
- **Kimi K2.7-Code scores 81.1% on MCPMark Verified tool invocation at $4/M output tokens:** Moonshot AI's open-source 1T-parameter MoE coding model (32B active, 384 experts, 256K context) beats Claude Opus 4.8's 76.4% on agentic tool-use benchmarks and is roughly 4x cheaper on output tokens; self-hosting requires 340GB INT4 weights via vLLM or SGLang. [Read more](https://app.daily.dev/posts/xNT5UhsOE)

---

Tags: [#security](https://daily.dev/tags/security), [#llm](https://daily.dev/tags/llm), [#ai-coding](https://daily.dev/tags/ai-coding)

[View this post on daily.dev](https://daily.dev/posts/spacex-acquires-cursor-for-60b-litellm-critical-rce-needs-patching-now-3m0ryfrwk)
