CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 13 More Stories

August 13, 2026

This week’s ThreatsDay Bulletin covers a wide range of cybersecurity developments, including new attack techniques, data breaches, and product updates. Key highlights include the GhostJacking attack that poisons AI agents, a ClickFix campaign using EtherHiding via the Polygon blockchain, and a critical flaw in Cursor’s CLI that allowed untrusted repository code execution. Other stories cover data breaches at ShipMonk, a vishing platform called Work Panel, and new features from Meta and Signal.

In the AI security space, GhostJacking expands on Agentjacking to trick AI agents into running arbitrary code, while Tracebit’s Context Bombs use prompt injections defensively. Malicious plugins are also transforming AI agents into insider threats. The Cursor CLI flaw, fixed after responsible disclosure, allowed cloned repositories to execute commands before trust prompts. ShipMonk suffered a data breach affecting customer order data, and Okta detailed the Work Panel vishing console used by threat actors like UNC6671.

Other notable items include a fake CCleaner distributing GhostDesk spyware, Apple paying a $150K bounty for a PCC flaw (CVE-2026-20685), and a new threat actor ExfilSquad targeting CRM and AI platforms. The bulletin also covers Chrome’s reduction of unwanted notifications, npm packages using NullReceiver to fetch malware, and an analysis of the crypter market.

CVEs: CVE-2026-20685

Attack groups: UNC6671, ExfilSquad, Cordial Spider

Malware: GhostDesk, ClickFix, NullReceiver

Companies: Reco, ShipMonk, Trezor, Cursor, Manifold Security, Okta, Tenet Security, Meta, Signal, Tracebit, Malwarebytes, Apple

Products: Salesforce Experience Cloud, ServiceNow Service Portal, Cursor CLI, WhatsApp Scam Alert, Signal Automatic Key Verification, Claude Desktop, Chrome, Firebase Cloud Messaging, Private Cloud Compute