⤷ Title: North Korean Hackers Pivot to AI: New npm Malware Targets Cursor, Claude, and Gemini Tokens
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 02:00:41 +0000
════════════════════════
⌗ Tags: #Malware #AI Tools #API Key Theft #Claude Code #Contagious Interview #Cursor AI #Cyberespionage #developer security #infosec #North Korea #npm malware #OtterCookie #WindSurf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 02:00:41 +0000
════════════════════════
⌗ Tags: #Malware #AI Tools #API Key Theft #Claude Code #Contagious Interview #Cursor AI #Cyberespionage #developer security #infosec #North Korea #npm malware #OtterCookie #WindSurf
Daily CyberSecurity
North Korean Hackers Pivot to AI: New npm Malware Targets Cursor, Claude, and Gemini Tokens
North Korean hackers are now targeting AI tools like Cursor and Claude. The OtterCookie malware steals API keys and conversation logs. Is your dev environment safe?
⤷ Title: The $600 Billion Orbit: SpaceX and xAI Join Forces with Cursor to Command the Future of Coding
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 09:48:29 +0000
════════════════════════
⌗ Tags: #Technology #AI Coding #artificial intelligence #Colossus Supercomputer #Cursor #Elon Musk #Software Engineering #SpaceX #SpaceX IPO #Tech Mergers 2026 #Vibe Coding #xAI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 09:48:29 +0000
════════════════════════
⌗ Tags: #Technology #AI Coding #artificial intelligence #Colossus Supercomputer #Cursor #Elon Musk #Software Engineering #SpaceX #SpaceX IPO #Tech Mergers 2026 #Vibe Coding #xAI
Daily CyberSecurity
The $600 Billion Orbit: SpaceX and xAI Join Forces with Cursor to Command the Future of Coding
SpaceX secures a $600 billion option to acquire Cursor AI. Discover how the "Vibe Coding" pioneer is leveraging xAI’s Colossus supercomputer to build the world's most powerful models.
⤷ Title: The AI Multiplier: How North Korea’s “HexagonalRodent” Turned ChatGPT into a $12M Crypto Heist
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 07:52:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChatGPT #Cryptocurrency Theft #Cursor AI #Cybercrime 2026 #Expel #Famous Chollima #HexagonalRodent #malware analysis #North Korea #Social Engineering #Web3 Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 07:52:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChatGPT #Cryptocurrency Theft #Cursor AI #Cybercrime 2026 #Expel #Famous Chollima #HexagonalRodent #malware analysis #North Korea #Social Engineering #Web3 Security
Penetration Testing Tools
The AI Multiplier: How North Korea’s "HexagonalRodent" Turned ChatGPT into a $12M Crypto Heist
Inexperienced North Korean cyber operatives have successfully exfiltrated millions of dollars in cryptocurrency over a span of several
⤷ Title: The Malware Factory: Unmasking the 108-Package North Korean Siege on npm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 06:30:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2026 #Blockchain C2 #CI/CD #Cursor AI #developer security #DPRK #infosec #malware #North Korea #npm #Panther Threat Research #Polymarket #supply chain attack #WindSurf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 06:30:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2026 #Blockchain C2 #CI/CD #Cursor AI #developer security #DPRK #infosec #malware #North Korea #npm #Panther Threat Research #Polymarket #supply chain attack #WindSurf
Daily CyberSecurity
The Malware Factory: Unmasking the 108-Package North Korean Siege on npm
Panther Research exposes a massive 2026 DPRK npm campaign using blockchain dead-drops to steal crypto keys and AI secrets. Secure your CI/CD pipelines now.
⤷ Title: Cursor AI IDE vulnerability allows code execution via hidden Git hooks
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 09:01:56 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #AI #Cursor AI #Cybersecurity #GitHib #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 09:01:56 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #AI #Cursor AI #Cybersecurity #GitHib #Vulnerability
Hackread
Cursor AI IDE vulnerability allows code execution via hidden Git hooks
Novee researchers find high-severity CVE-2026-26268 flaw in Cursor AI, allowing hackers to run malicious code when developers clone repositories.
⤷ Title: Cursor AI Agent Wipes PocketOS Database and Backups in 9 Seconds
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 21:31:34 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #AI #Claude Opus #Cursor AI #Cybersecurity #Jer Crane #PocketOS #Railway #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 21:31:34 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #AI #Claude Opus #Cursor AI #Cybersecurity #Jer Crane #PocketOS #Railway #Vulnerability
Hackread
Cursor AI Agent Wipes PocketOS Database and Backups in 9 Seconds
PocketOS founder says Cursor AI agent deleted its production database in 9 seconds after misusing a root API token, exposing major Railway security flaws
⤷ Title: The Sleeper in Your IDE: Unmasking the 73-Extension “GlassWorm” Espionage Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:01:51 +0000
════════════════════════
⌗ Tags: #Malware #.node binaries #Cursor AI #cyber_espionage #GlassWorm #IDE Security #infosec #Malware Analysis #Open VSX #Sleeper Extensions #Socket #VS Code #WindSurf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:01:51 +0000
════════════════════════
⌗ Tags: #Malware #.node binaries #Cursor AI #cyber_espionage #GlassWorm #IDE Security #infosec #Malware Analysis #Open VSX #Sleeper Extensions #Socket #VS Code #WindSurf
Daily CyberSecurity
The Sleeper in Your IDE: Unmasking the 73-Extension "GlassWorm" Espionage Campaign
Socket uncovers GlassWorm: a 73-extension sleeper campaign on Open VSX targeting VS Code and Cursor. Stealthy .node binaries turn trusted tools into malware.
⤷ Title: AI’s Open Secret: Why Your Cursor Extensions Can Silently Siphon Your API Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 07:11:58 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Code Editor #API keys #Credential Theft #Cursor AI #cybersecurity #Developer Tools #Extension Security #infosec #macOS #security vulnerability #SQLite #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 07:11:58 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Code Editor #API keys #Credential Theft #Cursor AI #cybersecurity #Developer Tools #Extension Security #infosec #macOS #security vulnerability #SQLite #windows
Daily CyberSecurity
AI’s Open Secret: Why Your Cursor Extensions Can Silently Siphon Your API Keys
Cursor AI editor found storing API keys and tokens in an unprotected SQLite database, allowing extensions to steal credentials silently. CVSS 8.2. No patch yet.
⤷ Title: Misconfigured Server Run by Hackers Leaks 345,000 Stolen Credit Cards
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 19:01:18 +0000
════════════════════════
⌗ Tags: #Security #Cyber Crime #Leaks #China #Credit Cards #Cursor #Cursor AI #Cybersecurity #Jerry’s Store #LEAKS #Misconfiguration #Privacy
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 19:01:18 +0000
════════════════════════
⌗ Tags: #Security #Cyber Crime #Leaks #China #Credit Cards #Cursor #Cursor AI #Cybersecurity #Jerry’s Store #LEAKS #Misconfiguration #Privacy
Hackread
Misconfigured Server Run by Hackers Leaks 345,000 Stolen Credit Cards
A misconfigured server tied to the carding marketplace Jerry’s Store exposed 345,000 stolen credit cards after an AI coding error caused a major security flaw.
⤷ Title: UNK_DeadDrop: North Korean Hackers Target Developers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Jun 2026 03:52:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cryptocurrency Theft #Cursor IDE #cybersecurity #Developer Phishing #GitHub malware #North Korean Hackers #UNK_DeadDrop
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Jun 2026 03:52:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cryptocurrency Theft #Cursor IDE #cybersecurity #Developer Phishing #GitHub malware #North Korean Hackers #UNK_DeadDrop
Information Security News
UNK_DeadDrop: North Korean Hackers Target Developers
North Korean hackers run the UNK_DeadDrop campaign, using fake job offers and GitHub repos to plant malware and steal crypto from developers.
⤷ Title: SpaceX Acquires Cursor for $60 Billion in AI Tech Buyout
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 01:47:15 +0000
════════════════════════
⌗ Tags: #Technology #AI Programming #Anysphere #Cursor #Elon Musk #SpaceX #Tech Acquisition
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 01:47:15 +0000
════════════════════════
⌗ Tags: #Technology #AI Programming #Anysphere #Cursor #Elon Musk #SpaceX #Tech Acquisition
Daily CyberSecurity
SpaceX Acquires Cursor for $60 Billion in AI Tech Buyout
Discover why SpaceX acquires Cursor for $60 billion. Explore how this monumental Anysphere buyout transforms AI programming and elevates Grok models.
⤷ Title: Give Your AI Agent a Real Browser: Setting Up Firefox DevTools MCP on macOS
════════════════════════
𐀪 Author: Cyphra
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 11:02:55 GMT
════════════════════════
⌗ Tags: #automation #pentesting #cybersecurity #cursor_ai #bug_bounty
════════════════════════
𐀪 Author: Cyphra
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 11:02:55 GMT
════════════════════════
⌗ Tags: #automation #pentesting #cybersecurity #cursor_ai #bug_bounty
Medium
Give Your AI Agent a Real Browser: Setting Up Firefox DevTools MCP on macOS
Imagine telling your AI assistant: “Open this staging app, log in, capture every API call, and tell me which endpoints look injectable.”
⤷ Title: Cursor iOS Beta App Brings Remote AI Coding to Mobile
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 04:41:38 +0000
════════════════════════
⌗ Tags: #Malware #Cursor AI #Developer Tools #iOS Beta #Remote Coding
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 04:41:38 +0000
════════════════════════
⌗ Tags: #Malware #Cursor AI #Developer Tools #iOS Beta #Remote Coding
Daily CyberSecurity
Cursor iOS Beta App Brings Remote AI Coding to Mobile
Recently, the AI-driven coding tool Cursor launched an iOS beta version. Fundamentally, this mobile application solves a major problem for developers. Previously, programmers had to carry their la…
⤷ Title: Critical Cursor IDE RCE Vulnerability Exposes Workspaces
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 14:24:44 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cursor IDE #CVE_2026_50548 #CVE_2026_50549 #DuneSlide attack #rce
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 14:24:44 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cursor IDE #CVE_2026_50548 #CVE_2026_50549 #DuneSlide attack #rce
Daily CyberSecurity
Critical Cursor IDE RCE Vulnerability Exposes Workspaces
TL;DR Cato AI Labs found a critical Cursor IDE RCE vulnerability. These bugs allow attackers to break out of the sandbox environment. Consequently, a threat actor can execute remote code on a vict…
⤷ Title: A Cursor Sandbox Escape Shows Why AI Agents Need Kernel Boundaries
════════════════════════
𐀪 Author: Hideaki Takahashi
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 20:23:41 GMT
════════════════════════
⌗ Tags: #ai_agent #cursor #hacking #security #claude_code
════════════════════════
𐀪 Author: Hideaki Takahashi
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 20:23:41 GMT
════════════════════════
⌗ Tags: #ai_agent #cursor #hacking #security #claude_code
Medium
A Cursor Sandbox Escape Shows Why AI Agents Need Kernel Boundaries
Cursor shipped a sandbox for agent-run commands, then two path-handling bugs let a malicious agent write outside it and reach full remote…
⤷ Title: GhostApproval Flaws Let Top AI Coding Tools Write Outside Workspaces
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 11:37:05 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #AI #Amazon #Anthropic #Augment #Cognition #Cursor #Cybersecurity #GhostApproval #Google #Privacy #Windsurf
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 11:37:05 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #AI #Amazon #Anthropic #Augment #Cognition #Cursor #Cybersecurity #GhostApproval #Google #Privacy #Windsurf
Hackread
GhostApproval Flaws Let Top AI Coding Tools Write Outside Workspaces
GhostApproval symlink flaws in major AI coding assistants could hide sensitive file targets, bypass approval checks and enable system access too.
⤷ Title: Cursor Builds General AI Agent to Rival Claude Cowork
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 03:18:55 +0000
════════════════════════
⌗ Tags: #Technology #AI agent #Anysphere #ChatGPT Work #Claude Cowork #Cursor AI #Desktop AI #General Purpose AI
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 03:18:55 +0000
════════════════════════
⌗ Tags: #Technology #AI agent #Anysphere #ChatGPT Work #Claude Cowork #Cursor AI #Desktop AI #General Purpose AI
Daily CyberSecurity
Cursor Builds General AI Agent to Rival Claude Cowork
Cursor is an AI code editor acquired by Elon Musk for 60 billion dollars. The company is reportedly preparing to leave its developer roots behind. The parent company, Anysphere, is quietly buildin…
⤷ Title: Cursor Zero-Day Vulnerability Remains Unpatched After Seven Months
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 09:51:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Coding Assistant #Cursor #Mindgard #Vulnerability #zero_day
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 09:51:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Coding Assistant #Cursor #Mindgard #Vulnerability #zero_day
Daily CyberSecurity
Cursor Zero-Day Vulnerability Remains Unpatched After Seven Months
The renowned cybersecurity firm Mindgard recently published an expose detailing a high-severity zero-day vulnerability harboring within Cursor, the prominent artificial intelligence coding assista…
⤷ Title: The Cursor Zero-Day That Sat Through 70 Versions
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Sun, 19 Jul 2026 06:07:29 GMT
════════════════════════
⌗ Tags: #cursor #zero_day #infosec #bug_bounty #windows
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Sun, 19 Jul 2026 06:07:29 GMT
════════════════════════
⌗ Tags: #cursor #zero_day #infosec #bug_bounty #windows
Medium
The Cursor Zero-Day That Sat Through 70 Versions
Cursor and HackerOne closed it as “informative, out of scope.” Seven months later, still no patch. So is it even a bug?