Daily Writeups
3.55K subscribers
2 photos
130K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Google Firebase Studio Launches as AI-Powered IDE Rival to Cursor AI
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 10 Apr 2025 10:22:34 +0000
════════════════════════
Tags: #Technology #AI IDE #artificial intelligence #Cloud IDE #Cursor AI #Gemini API #Google Firebase Studio #Programming #software development
Title: Malicious npm Packages Hit Over 3,200 Cursor Users with Sneaky Backdoor
════════════════════════
𐀪 Author: Farhan Ansari
════════════════════════
Time: Sat, 10 May 2025 19:23:19 GMT
════════════════════════
Tags: #security_systems #cybersecurity #cursor_ai #hacking #data_leak
Title: $500,000 Crypto Stolen: Fake AI Extension Targets Blockchain Devs via Open VSX
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Fri, 11 Jul 2025 03:30:08 +0000
════════════════════════
Tags: #Cybercriminals #blockchain #cryptocurrency #Cursor AI #cybersecurity #Infostealer #kaspersky #malware #Open VSX #Solidity #supply chain attack #VS Code
Title: Cursor AI IDE Hacked: Fraudulent Extension Steals $500K in Crypto from Russian Developer
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 15 Jul 2025 02:13:22 +0000
════════════════════════
Tags: #Cybercriminals #Crypto theft #cryptocurrency #Cursor AI #Extension #Infostealer #kaspersky #malware #Open VSX #PureLogs #ScreenConnect #Solidity #supply chain attack #visual studio code #VS Code
Title: Crypto Dev Loses $500K to Fake Cursor AI Extension: A New Supply Chain Threat
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 16 Jul 2025 03:06:08 +0000
════════════════════════
Tags: #Cybercriminals #cryptocurrency #Cursor AI #Info_stealer #malware #Open VSX #PureLogs #Quasar RAT #supply chain attack #Visual Studio Code
Title: Cursor AI’s “YOLO Mode” Exposed: Security Firm Warns of Easy Bypasses, Data Deletion, and RCE Risks
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 22 Jul 2025 22:48:07 +0000
════════════════════════
Tags: #Vulnerability #AI Agent #Backslash Security #Cursor AI #cybersecurity #File Deletion #Prompt Injection #remote code execution #vulnerability #YOLO Mode
Title: How a Cursor User Lost $500,000 from Crypto Wallet
════════════════════════
𐀪 Author: Mrinal Kanti Sardar
════════════════════════
Time: Mon, 28 Jul 2025 03:12:15 GMT
════════════════════════
Tags: #cyberattack #genai #hacking #cyber_security_awareness #cursor_ai
Title: MCPoison: How a Trusted AI Feature in Cursor Became a Hacker’s Backdoor (CVE-2025–54136)
════════════════════════
𐀪 Author: Atharva Shirude
════════════════════════
Time: Thu, 07 Aug 2025 01:14:07 GMT
════════════════════════
Tags: #ai_security #cybersecurity #cve #generative_ai_tools #cursor_ai
Title: Cursor as your Secure Dev Team
════════════════════════
𐀪 Author: Brett Crawley
════════════════════════
Time: Sat, 21 Feb 2026 18:29:34 GMT
════════════════════════
Tags: #application_security #secure_coding #cursor_ai
Title: The Gemini Trap: How a Fake AI Token Checker Stealthily Hijacks Developer Workstations
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 07 Apr 2026 07:52:30 +0000
════════════════════════
Tags: #Malware #Anthropic #Contagious Interview #Cursor AI #Cybersecurity 2026 #Developer Security #gemini_ai_checker #North Korea #NPM Malware #OtterCookie #supply chain attack #Windsurf
Title: North Korean Hackers Pivot to AI: New npm Malware Targets Cursor, Claude, and Gemini Tokens
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 10 Apr 2026 02:00:41 +0000
════════════════════════
Tags: #Malware #AI Tools #API Key Theft #Claude Code #Contagious Interview #Cursor AI #Cyberespionage #developer security #infosec #North Korea #npm malware #OtterCookie #WindSurf
Title: The AI Multiplier: How North Korea’s “HexagonalRodent” Turned ChatGPT into a $12M Crypto Heist
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Fri, 24 Apr 2026 07:52:06 +0000
════════════════════════
Tags: #Cybercriminals #ChatGPT #Cryptocurrency Theft #Cursor AI #Cybercrime 2026 #Expel #Famous Chollima #HexagonalRodent #malware analysis #North Korea #Social Engineering #Web3 Security
Title: The Malware Factory: Unmasking the 108-Package North Korean Siege on npm
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 29 Apr 2026 06:30:05 +0000
════════════════════════
Tags: #Cybercriminals #2026 #Blockchain C2 #CI/CD #Cursor AI #developer security #DPRK #infosec #malware #North Korea #npm #Panther Threat Research #Polymarket #supply chain attack #WindSurf
Title: Cursor AI IDE vulnerability allows code execution via hidden Git hooks
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
Time: Wed, 29 Apr 2026 09:01:56 +0000
════════════════════════
Tags: #Security #Artificial Intelligence #AI #Cursor AI #Cybersecurity #GitHib #Vulnerability
Title: Cursor AI Agent Wipes PocketOS Database and Backups in 9 Seconds
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
Time: Wed, 29 Apr 2026 21:31:34 +0000
════════════════════════
Tags: #Security #Artificial Intelligence #AI #Claude Opus #Cursor AI #Cybersecurity #Jer Crane #PocketOS #Railway #Vulnerability
Title: The Sleeper in Your IDE: Unmasking the 73-Extension “GlassWorm” Espionage Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 30 Apr 2026 08:01:51 +0000
════════════════════════
Tags: #Malware #.node binaries #Cursor AI #cyber_espionage #GlassWorm #IDE Security #infosec #Malware Analysis #Open VSX #Sleeper Extensions #Socket #VS Code #WindSurf
Title: AI’s Open Secret: Why Your Cursor Extensions Can Silently Siphon Your API Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 30 Apr 2026 07:11:58 +0000
════════════════════════
Tags: #Data Leak #AI Code Editor #API keys #Credential Theft #Cursor AI #cybersecurity #Developer Tools #Extension Security #infosec #macOS #security vulnerability #SQLite #windows
Title: Misconfigured Server Run by Hackers Leaks 345,000 Stolen Credit Cards
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
Time: Thu, 30 Apr 2026 19:01:18 +0000
════════════════════════
Tags: #Security #Cyber Crime #Leaks #China #Credit Cards #Cursor #Cursor AI #Cybersecurity #Jerry’s Store #LEAKS #Misconfiguration #Privacy