product · 4 records
Cursor

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Several AI coding agents are susceptible to remote code execution when they automatically run malicious commands defined in a repository's Git configuration file.

Aurora ransomware operators utilize Cursor AI for international cyberattacks
Threat actors associated with Aurora ransomware are using SpaceX's Cursor AI assistant to plan and execute attacks against targets in multiple countries, while a new AI-assisted toolkit named Gryxa has also been discovered.

Researchers warn AI coding agents are vulnerable to malicious package attacks
Researchers demonstrated that AI coding agents can be compromised by executing code from hallucinated package and repository names without verification.

Researchers identify sandbox escape vulnerabilities in four AI coding agents
Security researchers disclosed sandbox escape vulnerabilities in four AI coding agents—Cursor, OpenAI Codex, Google Gemini CLI, and Antigravity—by leveraging prompt injection and trusted local tool execution.