Related Threat Clusters
-
Kimsuky Expands AI Capabilities for Cyberattacks
The North Korean hacking group Kimsuky has developed local AI tools to enhance its cyberattack capabilities, as reported by Genians Security Center on August 10, 2026. The group is utilizing large language models (LLMs)…
49 articles · Updated August 10, 2026 -
Jscrambler npm Package Compromised in Supply Chain Attack
On July 11, 2026, multiple malicious versions of the jscrambler npm package were published, exploiting a compromised npm publishing credential. The affected versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0) included…
18 articles · Updated July 12, 2026 -
Cursor IDE Vulnerability Allows RCE via Malicious Git Repositories
A critical vulnerability in the Cursor IDE, tracked as CVE-2026-26268, has been disclosed, allowing arbitrary code execution (RCE) on developers' machines. The flaw arises from the interaction between Cursor's AI agent…
3 articles · Updated April 29, 2026 -
Vibe Coding Tools Found to Generate Critical Security Flaws
A study by security startup Tenzai revealed that popular vibe coding platforms produce insecure code, including critical vulnerabilities, when responding to common programming prompts. The assessment, conducted in…
3 articles · Updated January 14, 2026 -
Critical RCE Vulnerabilities in Cursor IDE Enable Zero-Click Prompt Injection Attacks
Cato AI Labs disclosed two critical remote code execution (RCE) vulnerabilities in Cursor IDE, tracked as CVE-2026-50548 and CVE-2026-50549. These vulnerabilities allow attackers to exploit zero-click prompt injection,…
37 articles · Updated July 1, 2026 -
HexagonalRodent Targets Web3 Developers with Social Engineering Attacks
The Lazarus Group's HexagonalRodent faction is targeting Web3 developers using social engineering tactics, including fake job offers for high-paying remote positions and recruitment for well-known projects. These…
2 articles · Updated April 25, 2026 -
AI Coding Agents Expand Software Supply Chain Risks
AI coding agents are introducing significant vulnerabilities into the software supply chain by selecting insecure dependencies without human oversight. Research indicates that only 20% of dependency versions recommended…
7 articles · Updated July 27, 2026 -
New Cryptographic Context Injection Attack Targets AI Coding Agents
A novel attack technique named Cryptographic Context Injection has been identified, allowing attackers to inject malicious instructions into AI models like Grok and Gemini. This method involves shipping encrypted…
11 articles · Updated August 20, 2026 -
Glassworm Botnet Targeting Developers Disrupted by CrowdStrike and Google
The Glassworm botnet, which has targeted software developers since early 2025, was taken down in a coordinated operation by CrowdStrike, Google, and the Shadowserver Foundation on May 26, 2026. This botnet utilized…
30 articles · Updated May 27, 2026 -
Google's Antigravity IDE Vulnerability Allows Remote Code Execution via Prompt Injection
Researchers at Pillar Security discovered a critical prompt injection vulnerability in Google's Antigravity IDE, which allows for remote code execution (RCE) by exploiting insufficient input sanitization in the…
4 articles · Updated April 20, 2026
Recent Intelligence Reports
- Musk's Cursor AI used in Russia linked hit on seven firms as insurers race to rewrite cyber cover — Insurancebusinessmag · August 28, 2026
- Hackers used Cursor AI agent to breach seven companies — Resultsense · August 28, 2026
- Russian-speaking cybercriminals used SpaceX's Cursor AI tool to hack seven companies — Rnz.Co.Nz · August 28, 2026
- Reuters: Russian — Meduza · August 27, 2026
- Agentic AI Security: Credentials and Permissions Define the Blast Radius — Blog.Gitguardian · August 25, 2026
- SymJack attack — adversa.ai · August 20, 2026
- Docker warns of hidden dangers in AI agent command approval — Finance.Biggo · August 19, 2026
- Cursor Cli Worktree Pre Trust Execution — www.manifold.security · August 12, 2026