Rogue MCP Servers Exploit Vulnerability in Cursor's Internal Browser
Article Content
Browse articles
Hackers are exploiting a critical vulnerability in Cursor, an AI-powered code editor, by using compromised Model Context Protocol (MCP) servers to inject malicious code. This attack allows the rogue servers to manipulate Cursor's internal browser, potentially replacing legitimate login pages with attacker-controlled ones. The lack of integrity verification in Cursor's proprietary features makes it particularly susceptible to these attacks.
Ask AI about this cluster
Answers cite the sources they use
Updated 202d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track XWorm, Cursor and CVE-2025-64446 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Cybercriminals Use Fake AI Agents to Steal Crypto Wallets Cybercriminals are exploiting interest in Agentic AI by creating fake AI trading agents to lure crypto users into downloading malware. This malware, known as Needle Stealer, replaces legitimate browser wallet extensions like MetaMask and Coinbase with malicious versions that capture user credentials. The attacks were…
Surge in Exploited CVEs and Malware Activity in H1 2026 In the first half of 2026, Insikt Group reported 215 actively exploited CVEs, marking a 34% increase from the previous year. Notably, AsyncRAT emerged as the leading malware, with nearly 60,000 unique hashes. The report highlighted a significant rise in NFC-based Android attacks, which surged by 188%. Threat actors…