Friendly Fire Attack: AI Coding Agents Tricked Into Running Malicious Code
Researchers at the AI Now Institute have published a proof-of-concept attack called 'Friendly Fire' that exploits AI coding agents designed to catch…
Researchers at the AI Now Institute have published a proof-of-concept attack called 'Friendly Fire' that exploits AI coding agents designed to catch…
Security researchers at Wiz have identified a critical vulnerability pattern, dubbed GhostApproval, affecting six popular AI coding assistants. The flaw allows a…
Sophos has identified that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are triggering endpoint security rules originally designed…
Researchers from Tel Aviv University, Technion, and Intuit have identified a novel attack vector called HalluSquatting that exploits AI coding assistants' tendency…
North Korean threat actors linked to the Contagious Interview campaign have published 108 unique malicious packages and browser extensions across npm, Packagist,…
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup…
Two critical vulnerabilities in Cursor, an AI-powered code editor, allow prompt injection attacks to escape the editor's safety sandbox and execute arbitrary…
CVE-2025-54135, known as CurXecute, is a vulnerability in Cursor discovered by Aim Security. A planted Slack message rewrites Cursor's ~/.cursor/mcp.json config and…
A Git-hook sandbox escape vulnerability in Cursor, reported by Novee under coordinated disclosure and fixed in Cursor 2.5 on February 13, 2026.
Cursor fixed a CLI vulnerability that allowed cloned repositories to execute commands before trust prompts, even with sandbox enabled.