Tag

#Cursor

15 stories taggedCursor.

A developer's IDE showing a Git repository with booby-trapped configuration files, with command execution logs and security alerts appearing in the terminal bel
AI Security

Poisoned Git Configs Trick Claude, Codex and Cursor Into Running Attacker Code

Manifold Security found eight flaws in seven command-line AI coding assistants that let a booby-trapped repository run commands on a developer's machine without asking permission.

4 min read
A hacker's workstation showing an AI code assistant interface on one monitor and a network intrusion diagram on another, Russian-language system prompts visible
Ransomware

Aurora ransomware crew caught using Cursor AI to break into networks

Researchers at CloudSEK and Gambit Security independently tie a Russian-speaking gang to at least 10 intrusions built with help from an AI coding assistant backed by SpaceX.

4 min read
A busy security operations center wall displaying multiple stacked windows and alerts from different security tools, creating a complex layered visual of interc
Threat Intelligence

This Week's Security Grab Bag: AI Hijacks, Fake Fixes, and a Cursor Bug

A roundup week: nothing catastrophic on its own, but the patterns are the story.

4 min read
A developer's code editor showing configuration files for an AI coding assistant, with hidden credential theft mechanisms embedded in what appears to be innocuo
AI Security

Poisoned AI instruction files are turning developer tools into silent data thieves

Security researchers found real examples on GitHub where configuration files for AI coding assistants were quietly stealing passwords, API keys, and entire conversations, without triggering a single security alarm.

5 min read
A security research lab demonstrating a sandboxed AI coding agent environment, with file transfer operations visible on screen and permission architecture diagr
AI Security

AI Coding Assistants Can Slip Past Their Own Security Cages Without Breaking Them

New research from Pillar Security shows that the sandboxes meant to contain AI coding agents have a fundamental blind spot: the agent never needs to escape if it can simply hand a poisoned file to something that already has permission to run it.

3 min read
Illustration: a developer's darkened desk at night
AI Security

AI coding assistants get tricked into hacking their own developers

Researchers show that Cursor, OpenAI's Codex, Google's Gemini CLI and Antigravity can be nudged to write files that trusted tools outside the safety box then happily run.

4 min read
Illustration: a developer's dark home office desk at night
Vulnerabilities

Cursor on Windows Runs Rogue git.exe From Any Opened Repo, No Warning

A flaw in the AI code editor lets a booby-trapped repository execute code on a developer's machine the moment the folder is opened.

4 min read
Illustration: a dimly lit server rack with green and amber LEDs reflecting off glossy black metal
Vulnerabilities

Popular AI Coding Tool Cursor Runs Malicious Files Automatically, Researcher Warns

A security firm reported the flaw seven months ago and got silence. Now it's gone public.

3 min read
Illustration: On the screen, a software approval dialog box glows in blue and white
AI Security

GhostApproval: Six AI Coding Tools Were Tricking Developers Into Approving Dangerous Actions

A new attack pattern shows that the 'human approval' step built into AI coding assistants can be fed false information by the very tool it is supposed to oversee.

4 min read
Illustration: A dark wooden desk seen from slightly above
AI Security

AI Coding Assistants Fooled by Decades-Old File Trick to Attack Developer Machines

A technique as old as Unix itself let researchers plant hidden traps inside innocent-looking code projects, then watch AI tools quietly rewrite the wrong files while developers clicked 'approve'.

3 min read
Illustration: a modern developer workstation at dusk, two large monitors glowing with abstract code editor windows
AI Security

A trick in six AI coding helpers lets a poisoned project hijack your laptop

Researchers at Wiz found that popular AI coding assistants, including Amazon Q Developer and Claude Code, can be fooled into writing to sensitive files while asking permission for a harmless one.

3 min read
Illustration: a developer workstation at night, two large monitors filled with code and a security dashboard showing red
AI Security

When your AI coder looks exactly like a hacker to the security software

Sophos found that popular AI coding assistants keep tripping the same alarms designed to spot break-ins, and the false alerts are piling up.

4 min read
Illustration: a mechanical keyboard on a dark desk
Vulnerabilities

Popular AI Coding Tool Cursor Has Flaws That Could Let Attackers Run Code on Your Computer

Security researchers found two vulnerabilities in the Cursor AI code editor that could allow an attacker to silently take control of a developer's machine, no click required.

3 min read
Macro photograph of a glowing computer terminal screen in a dark room displaying cascading green lines of code and error log text, with a single line subtly hig
AI Security

A Fake Error Message Hijacked AI Coding Assistants — and Security Tools Saw Nothing

Researchers planted a single bogus bug report in a popular developer service and watched AI coding agents obediently run the attackers' code. No password stolen. No alarm raised.

3 min read
Illustration: a developer's darkened desk at night
AI Security

DuneSlide: Two Cursor Bugs Turn a Prompt Into a Shell

A pair of 9.8-rated flaws in the AI code editor let a single crafted prompt escape the sandbox and execute arbitrary commands, no user approval required.

3 min read
© 2026 Threat Vectr