Critical Cursor Flaws Enable Zero-Click Sandbox Escape via Prompt Injection
Two critical vulnerabilities in Cursor, an AI-powered code editor, allow prompt injection attacks to escape the editor's safety sandbox and execute arbitrary…
Two critical vulnerabilities in Cursor, an AI-powered code editor, allow prompt injection attacks to escape the editor's safety sandbox and execute arbitrary…
watchTowr is a preemptive exposure management firm that identified active exploitation of CVE-2026-19478 in its honeypot network. The company emphasizes the accelerating…
The Zero Day Initiative counted 398 CVEs in Microsoft's August 2026 release, with 62 rated Critical, and described the DNS Server flaw…
OpenAI has released three versions of GPT-5.6—Sol, Terra, and Luna—as a limited preview to a small number of companies in coordination with…
Wiz Research discovered and reported the Amazon Q Developer flaw, demonstrating the attack vector and coordinating with Amazon for the fix.
TrendAI's Zero Day Initiative and research team reported the Oracle PeopleSoft vulnerability to Oracle.
The U.S. government has ordered Anthropic to suspend access to its most advanced AI models, Claude Fable 5 and Mythos 5, for…
Endor Labs, a cybersecurity company, identified a critical vulnerability in the isolated-vm Node.js library. The flaw, GHSA-864f-rcv7-6rh4, allows sandboxed code to escape…
CyStack's Trung Nguyen discovered and reported two critical vulnerabilities in NGINX Open Source, leading to patches from F5.
Zafran Security is a cybersecurity company that discovered and disclosed the DifyTap vulnerabilities in Dify, including critical flaws enabling cross-tenant data exfiltration.…