Cursor just doubled in 6 months

Cursor is set to raise $2 billion at a $50 billion valuation, fueled by rapid growth and strong customer adoption. OX Security reveals critical vulnerabilities in Anthropic's Model Context Protocol affecting numerous popular projects.

Cursor just doubled. CNBC reports Cursor is in talks to raise $2 billion at a $50 billion-plus pre-money valuation, co-led by Andreessen Horowitz and Thrive Capital with Nvidia as strategic co-investor and Battery Ventures joining as a new backer. That is roughly double the $29.3 billion post-money mark set in November 2025—six months ago. The ARR curve explains the appetite: $100 million in January 2025, $500 million by June, $1 billion by November, and $2 billion by February 2026, with internal projections of more than $6 billion ARR by year-end. Cursor counts roughly 360,000 paying customers and says 64% of the Fortune 500 now use the product, framing itself as the fastest-scaling B2B software business on record—ahead of Slack, Zoom, and Snowflake at the $2 billion ARR mark. The round is already oversubscribed. At a projected $6 billion ARR, a $50 billion valuation compresses to roughly 8x revenue—a multiple that only works if the triple-digit growth holds.

The rails underneath that stack just got a closer look. OX Security disclosed 10 CVEs tied to the STDIO execution model in Anthropic’s Model Context Protocol, the spec that powers plugin ecosystems across Cursor, Claude Code, and thousands of agent frameworks. The research identifies 7,000-plus publicly accessible MCP servers and more than 150 million downloads across impacted packages, with identical flawed behavior reproduced across Anthropic’s official SDKs in Python, TypeScript, Java, and Rust. The CVE list spans widely used projects—CVE-2025-65720 in GPT Researcher, CVE-2026-30623 in LiteLLM, CVE-2026-30624 in Agent Zero, CVE-2026-40933 in Flowise, and CVE-2025-49596 in MCP Inspector. LiteLLM, DocsGPT, Flowise, and Bisheng have shipped patches; LangFlow, Agent Zero, and Fay Framework remain unresolved at the application layer. Anthropic declined to modify the architecture, characterizing the execution behavior as “expected” and placing input sanitization on developers. The researcher’s summary: “one architectural decision propagated silently into every language, every downstream library.” The protocol is now load-bearing for the agent economy, and the patching responsibility sits downstream of the spec owner.

While the app layer consolidates, the silicon layer is fragmenting. The Next Web reports Google is in talks with Marvell on two new chips—a memory processing unit and an inference-optimized TPU—making Marvell its third TPU design partner alongside Broadcom and MediaTek. The fabricator has not been publicly disclosed. Broadcom is locked in as Google’s high-performance TPU partner through 2031 and currently commands more than 70% of the custom AI accelerator market; Counterpoint Research projects Broadcom holds about 60% share in 2027, with Marvell’s design-services share near 8%. MediaTek continues to build cost-optimized “e” variants at 20–30% lower cost. The custom AI chip market is projected to grow 45% in 2026 and reach $118 billion by 2033, with inference increasingly favoring purpose-built silicon over general-purpose GPUs. Nvidia—whose $2 billion strategic investment in Marvell closed at the end of March through the NVLink Fusion partnership—now holds equity in the same custom-silicon designer whose inference chips are built to compete with Nvidia’s own GPUs. Three partners per hyperscaler is the new default, and inference is where the revenue compounds.

That’s Monday. Three stories, zero fluff.

— The PulseMark Team

Get the Daily Pulse

Sharp analysis on what's actually moving in AI. No hype, no filler, no weekly digest.

Get the Daily Pulse

Sharp AI analysis, daily. Two minutes, every morning.

Get the Daily PulseTwo minutes, every morning