This Week's Security Grab Bag: AI Hijacks, Fake Fixes, and a Cursor Bug
A roundup week: nothing catastrophic on its own, but the patterns are the story.

Key points
- The Hacker News published its ThreatsDay bulletin covering roughly 20 smaller security stories from the past week.
- The batch spans cloud services, AI tools, malware, and new attack techniques.
- Highlights include a technique called GhostJacking that targets AI agents, EtherHiding abuse via the ClickFix scam, and a flaw in the Cursor command-line tool used by developers.
- No single item is a headline-grabber, but together they show where attackers are pushing next.
- Security teams get a quick catch-up; developers and end users each have one concrete action.
Some weeks in this job hand you a single, ugly story: a ransomware crew, which is a criminal gang that locks up a company's files and demands payment, takes down a hospital chain. Other weeks are quieter on the surface but noisier underneath. This is one of those.
The Hacker News rolled up around twenty smaller items into its ThreatsDay bulletin. On their own, none of them will make the evening news. Read together, they tell you where attackers are spending their time.
What actually happened this week?
A lot of small things, across a lot of surfaces. The bulletin sweeps across cloud platforms, AI assistants, everyday malware, fresh data leaks, and a handful of new attack tricks researchers have named for the first time.
Three items stand out.
The first is GhostJacking, an attack aimed at AI agents. An AI agent is a program that acts on your behalf, clicking links, filling forms, moving money. GhostJacking tricks that helper into acting on planted instructions hidden inside content it reads. We covered the technique in depth on 10 August, when researchers showed a single blocked web request was enough to hand over a company's entire domain. The failure mode is the same one every AI vendor keeps waving away: the agent can't reliably tell an instruction from a piece of data.
The second is EtherHiding paired with ClickFix. ClickFix is a scam where a fake error message tells you to paste a "fix" into your computer to solve a problem that doesn't exist. What you paste is a command that installs malware. EtherHiding hides the malicious payload inside the Ethereum blockchain, the public ledger that powers the cryptocurrency, giving attackers storage that's nearly impossible to take down. We've tracked EtherHiding across five stories since 20 July, including two separate ClickFix campaigns Microsoft flagged that ran between late April and mid-June 2026.
The third is a flaw in Cursor's command-line tool. Cursor is an AI-assisted code editor that a lot of developers use daily. We reported in July that a booby-trapped repository could execute code the moment a developer opened the folder. This week's bulletin adds a related CLI (command-line interface) variant. If you build software for a living, update now.
Should ordinary people care?
Yes, but only about two of the items. If a website ever tells you to open a terminal or the Windows Run box and paste something in, close the tab. That's ClickFix. No legitimate error message on a real website asks you to do that.
The other one worth knowing: as AI assistants get more power to act for you, treat them like a new employee on day one, not a trusted deputy. Be careful what you let them read and click.
What should security teams actually do with this?
Triage it. A bulletin like this isn't a to-do list; it's a signal of drift. Attackers are pushing on AI agents, developer tooling, and scams that get the victim to type the malicious command themselves.
| Item | Who it hits | What to do |
|---|---|---|
| GhostJacking | Teams deploying AI agents | Lock down what the agent can execute; log every action |
| EtherHiding + ClickFix | End users, helpdesks | Block clipboard-paste-to-run flows; brief staff |
| Cursor CLI flaw | Developers | Update to the latest Cursor release |
Whichever of these bites you first, the post-mortem will say the same thing it always says: nobody owned the risk before it was a headline.
If your detection stack still assumes the attacker is a human at a keyboard, you're already a week behind.



