A new attack named MemGhost demonstrates how a single email can inject persistent false memories into AI personal assistants, manipulating their future…
AI SecurityAim SecurityClaude Code SDKCVE-2025-32711
Two critical vulnerabilities in Cursor, an AI-powered code editor, allow prompt injection attacks to escape the editor's safety sandbox and execute arbitrary…
AI Code EditorAim SecurityCato AI LabsCheck Point Research
CVE-2025-54135, known as CurXecute, is a vulnerability in Cursor discovered by Aim Security. A planted Slack message rewrites Cursor's ~/.cursor/mcp.json config and…
A critical vulnerability in Microsoft 365 Copilot Enterprise Search, dubbed SearchLeak, could have allowed attackers to exfiltrate emails, files, and MFA codes…
Aim Security is a cybersecurity company that disclosed the EchoLeak vulnerability (CVE-2025-32711) in Microsoft 365 Copilot in June 2025. The flaw allowed…