⤷ Title: Google Firebase Studio Launches as AI-Powered IDE Rival to Cursor AI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 10:22:34 +0000
════════════════════════
⌗ Tags: #Technology #AI IDE #artificial intelligence #Cloud IDE #Cursor AI #Gemini API #Google Firebase Studio #Programming #software development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 10:22:34 +0000
════════════════════════
⌗ Tags: #Technology #AI IDE #artificial intelligence #Cloud IDE #Cursor AI #Gemini API #Google Firebase Studio #Programming #software development
Daily CyberSecurity
Google Firebase Studio Launches as AI-Powered IDE Rival to Cursor AI
Google launches Firebase Studio, an AI-powered cloud IDE rivaling Cursor AI, enabling code generation from natural language and images. Users need a Gemini API key.
⤷ Title: Malicious npm Packages Hit Over 3,200 Cursor Users with Sneaky Backdoor
════════════════════════
𐀪 Author: Farhan Ansari
════════════════════════
ⴵ Time: Sat, 10 May 2025 19:23:19 GMT
════════════════════════
⌗ Tags: #security_systems #cybersecurity #cursor_ai #hacking #data_leak
════════════════════════
𐀪 Author: Farhan Ansari
════════════════════════
ⴵ Time: Sat, 10 May 2025 19:23:19 GMT
════════════════════════
⌗ Tags: #security_systems #cybersecurity #cursor_ai #hacking #data_leak
Medium
Malicious npm Packages Hit Over 3,200 Cursor Users with Sneaky Backdoor
Imagine you’re a developer, excited to try out a new tool that promises cheap access to Cursor, the AI-powered code editor everyone’s…
⤷ Title: $500,000 Crypto Stolen: Fake AI Extension Targets Blockchain Devs via Open VSX
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 03:30:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #blockchain #cryptocurrency #Cursor AI #cybersecurity #Infostealer #kaspersky #malware #Open VSX #Solidity #supply chain attack #VS Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 03:30:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #blockchain #cryptocurrency #Cursor AI #cybersecurity #Infostealer #kaspersky #malware #Open VSX #Solidity #supply chain attack #VS Code
Penetration Testing Tools
$500,000 Crypto Stolen: Fake AI Extension Targets Blockchain Devs via Open VSX
A Russian blockchain developer lost $500,000 to a malicious VS Code extension disguised as a Solidity tool on Open VSX, highlighting supply chain risks for devs.
⤷ Title: Cursor AI IDE Hacked: Fraudulent Extension Steals $500K in Crypto from Russian Developer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:13:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto theft #cryptocurrency #Cursor AI #Extension #Infostealer #kaspersky #malware #Open VSX #PureLogs #ScreenConnect #Solidity #supply chain attack #visual studio code #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:13:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto theft #cryptocurrency #Cursor AI #Extension #Infostealer #kaspersky #malware #Open VSX #PureLogs #ScreenConnect #Solidity #supply chain attack #visual studio code #VS Code
Daily CyberSecurity
Cursor AI IDE Hacked: Fraudulent Extension Steals $500K in Crypto from Russian Developer
A Russian crypto developer lost $500K after installing a fraudulent "Solidity Language" extension for Cursor AI IDE from Open VSX, which deployed malware for remote access and data theft.
⤷ Title: Crypto Dev Loses $500K to Fake Cursor AI Extension: A New Supply Chain Threat
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 16 Jul 2025 03:06:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cryptocurrency #Cursor AI #Info_stealer #malware #Open VSX #PureLogs #Quasar RAT #supply chain attack #Visual Studio Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 16 Jul 2025 03:06:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cryptocurrency #Cursor AI #Info_stealer #malware #Open VSX #PureLogs #Quasar RAT #supply chain attack #Visual Studio Code
Penetration Testing Tools
Crypto Dev Loses $500K to Fake Cursor AI Extension: A New Supply Chain Threat
A Russian crypto developer lost $500K due to a malicious "Solidity Language" extension on Open VSX for Cursor AI, highlighting new supply chain risks.
⤷ Title: Cursor AI’s “YOLO Mode” Exposed: Security Firm Warns of Easy Bypasses, Data Deletion, and RCE Risks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 22:48:07 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Agent #Backslash Security #Cursor AI #cybersecurity #File Deletion #Prompt Injection #remote code execution #vulnerability #YOLO Mode
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 22:48:07 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Agent #Backslash Security #Cursor AI #cybersecurity #File Deletion #Prompt Injection #remote code execution #vulnerability #YOLO Mode
Penetration Testing Tools
Cursor AI's "YOLO Mode" Exposed: Security Firm Warns of Easy Bypasses, Data Deletion, and RCE Risks
Backslash Security warns that Cursor AI's "YOLO mode" (unsupervised execution) has easily bypassed safeguards, risking file deletion, arbitrary code execution, and data compromise via simple command obfuscation.
⤷ Title: How a Cursor User Lost $500,000 from Crypto Wallet
════════════════════════
𐀪 Author: Mrinal Kanti Sardar
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 03:12:15 GMT
════════════════════════
⌗ Tags: #cyberattack #genai #hacking #cyber_security_awareness #cursor_ai
════════════════════════
𐀪 Author: Mrinal Kanti Sardar
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 03:12:15 GMT
════════════════════════
⌗ Tags: #cyberattack #genai #hacking #cyber_security_awareness #cursor_ai
Medium
How a Cursor User Lost $500,000 from Crypto Wallet
A Devastating Supply Chain Attack
⤷ Title: MCPoison: How a Trusted AI Feature in Cursor Became a Hacker’s Backdoor (CVE-2025–54136)
════════════════════════
𐀪 Author: Atharva Shirude
════════════════════════
ⴵ Time: Thu, 07 Aug 2025 01:14:07 GMT
════════════════════════
⌗ Tags: #ai_security #cybersecurity #cve #generative_ai_tools #cursor_ai
════════════════════════
𐀪 Author: Atharva Shirude
════════════════════════
ⴵ Time: Thu, 07 Aug 2025 01:14:07 GMT
════════════════════════
⌗ Tags: #ai_security #cybersecurity #cve #generative_ai_tools #cursor_ai
Medium
MCPoison: How a Trusted AI Feature in Cursor Became a Hacker’s Backdoor (CVE-2025–54136)
MCP, short for Multi-Command Package, is a feature in the Cursor AI code editor designed to streamline developer workflows. Think of it as a way to automate common tasks — like testing, building, or…
⤷ Title: Cursor as your Secure Dev Team
════════════════════════
𐀪 Author: Brett Crawley
════════════════════════
ⴵ Time: Sat, 21 Feb 2026 18:29:34 GMT
════════════════════════
⌗ Tags: #application_security #secure_coding #cursor_ai
════════════════════════
𐀪 Author: Brett Crawley
════════════════════════
ⴵ Time: Sat, 21 Feb 2026 18:29:34 GMT
════════════════════════
⌗ Tags: #application_security #secure_coding #cursor_ai
Medium
Cursor as your Secure Dev Team
What I wanted
⤷ Title: The Gemini Trap: How a Fake AI Token Checker Stealthily Hijacks Developer Workstations
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 07:52:30 +0000
════════════════════════
⌗ Tags: #Malware #Anthropic #Contagious Interview #Cursor AI #Cybersecurity 2026 #Developer Security #gemini_ai_checker #North Korea #NPM Malware #OtterCookie #supply chain attack #Windsurf
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 07:52:30 +0000
════════════════════════
⌗ Tags: #Malware #Anthropic #Contagious Interview #Cursor AI #Cybersecurity 2026 #Developer Security #gemini_ai_checker #North Korea #NPM Malware #OtterCookie #supply chain attack #Windsurf
Penetration Testing Tools
The Gemini Trap: How a Fake AI Token Checker Stealthily Hijacks Developer Workstations
An ostensibly innocuous package for validating Google Gemini tokens manifested within the npm repository, yet beneath its rudimentary
⤷ Title: North Korean Hackers Pivot to AI: New npm Malware Targets Cursor, Claude, and Gemini Tokens
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 02:00:41 +0000
════════════════════════
⌗ Tags: #Malware #AI Tools #API Key Theft #Claude Code #Contagious Interview #Cursor AI #Cyberespionage #developer security #infosec #North Korea #npm malware #OtterCookie #WindSurf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 02:00:41 +0000
════════════════════════
⌗ Tags: #Malware #AI Tools #API Key Theft #Claude Code #Contagious Interview #Cursor AI #Cyberespionage #developer security #infosec #North Korea #npm malware #OtterCookie #WindSurf
Daily CyberSecurity
North Korean Hackers Pivot to AI: New npm Malware Targets Cursor, Claude, and Gemini Tokens
North Korean hackers are now targeting AI tools like Cursor and Claude. The OtterCookie malware steals API keys and conversation logs. Is your dev environment safe?
⤷ Title: The AI Multiplier: How North Korea’s “HexagonalRodent” Turned ChatGPT into a $12M Crypto Heist
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 07:52:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChatGPT #Cryptocurrency Theft #Cursor AI #Cybercrime 2026 #Expel #Famous Chollima #HexagonalRodent #malware analysis #North Korea #Social Engineering #Web3 Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 07:52:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChatGPT #Cryptocurrency Theft #Cursor AI #Cybercrime 2026 #Expel #Famous Chollima #HexagonalRodent #malware analysis #North Korea #Social Engineering #Web3 Security
Penetration Testing Tools
The AI Multiplier: How North Korea’s "HexagonalRodent" Turned ChatGPT into a $12M Crypto Heist
Inexperienced North Korean cyber operatives have successfully exfiltrated millions of dollars in cryptocurrency over a span of several
⤷ Title: The Malware Factory: Unmasking the 108-Package North Korean Siege on npm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 06:30:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2026 #Blockchain C2 #CI/CD #Cursor AI #developer security #DPRK #infosec #malware #North Korea #npm #Panther Threat Research #Polymarket #supply chain attack #WindSurf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 06:30:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2026 #Blockchain C2 #CI/CD #Cursor AI #developer security #DPRK #infosec #malware #North Korea #npm #Panther Threat Research #Polymarket #supply chain attack #WindSurf
Daily CyberSecurity
The Malware Factory: Unmasking the 108-Package North Korean Siege on npm
Panther Research exposes a massive 2026 DPRK npm campaign using blockchain dead-drops to steal crypto keys and AI secrets. Secure your CI/CD pipelines now.
⤷ Title: Cursor AI IDE vulnerability allows code execution via hidden Git hooks
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 09:01:56 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #AI #Cursor AI #Cybersecurity #GitHib #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 09:01:56 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #AI #Cursor AI #Cybersecurity #GitHib #Vulnerability
Hackread
Cursor AI IDE vulnerability allows code execution via hidden Git hooks
Novee researchers find high-severity CVE-2026-26268 flaw in Cursor AI, allowing hackers to run malicious code when developers clone repositories.
⤷ Title: Cursor AI Agent Wipes PocketOS Database and Backups in 9 Seconds
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 21:31:34 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #AI #Claude Opus #Cursor AI #Cybersecurity #Jer Crane #PocketOS #Railway #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 21:31:34 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #AI #Claude Opus #Cursor AI #Cybersecurity #Jer Crane #PocketOS #Railway #Vulnerability
Hackread
Cursor AI Agent Wipes PocketOS Database and Backups in 9 Seconds
PocketOS founder says Cursor AI agent deleted its production database in 9 seconds after misusing a root API token, exposing major Railway security flaws
⤷ Title: The Sleeper in Your IDE: Unmasking the 73-Extension “GlassWorm” Espionage Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:01:51 +0000
════════════════════════
⌗ Tags: #Malware #.node binaries #Cursor AI #cyber_espionage #GlassWorm #IDE Security #infosec #Malware Analysis #Open VSX #Sleeper Extensions #Socket #VS Code #WindSurf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:01:51 +0000
════════════════════════
⌗ Tags: #Malware #.node binaries #Cursor AI #cyber_espionage #GlassWorm #IDE Security #infosec #Malware Analysis #Open VSX #Sleeper Extensions #Socket #VS Code #WindSurf
Daily CyberSecurity
The Sleeper in Your IDE: Unmasking the 73-Extension "GlassWorm" Espionage Campaign
Socket uncovers GlassWorm: a 73-extension sleeper campaign on Open VSX targeting VS Code and Cursor. Stealthy .node binaries turn trusted tools into malware.
⤷ Title: AI’s Open Secret: Why Your Cursor Extensions Can Silently Siphon Your API Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 07:11:58 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Code Editor #API keys #Credential Theft #Cursor AI #cybersecurity #Developer Tools #Extension Security #infosec #macOS #security vulnerability #SQLite #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 07:11:58 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Code Editor #API keys #Credential Theft #Cursor AI #cybersecurity #Developer Tools #Extension Security #infosec #macOS #security vulnerability #SQLite #windows
Daily CyberSecurity
AI’s Open Secret: Why Your Cursor Extensions Can Silently Siphon Your API Keys
Cursor AI editor found storing API keys and tokens in an unprotected SQLite database, allowing extensions to steal credentials silently. CVSS 8.2. No patch yet.
⤷ Title: Misconfigured Server Run by Hackers Leaks 345,000 Stolen Credit Cards
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 19:01:18 +0000
════════════════════════
⌗ Tags: #Security #Cyber Crime #Leaks #China #Credit Cards #Cursor #Cursor AI #Cybersecurity #Jerry’s Store #LEAKS #Misconfiguration #Privacy
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 19:01:18 +0000
════════════════════════
⌗ Tags: #Security #Cyber Crime #Leaks #China #Credit Cards #Cursor #Cursor AI #Cybersecurity #Jerry’s Store #LEAKS #Misconfiguration #Privacy
Hackread
Misconfigured Server Run by Hackers Leaks 345,000 Stolen Credit Cards
A misconfigured server tied to the carding marketplace Jerry’s Store exposed 345,000 stolen credit cards after an AI coding error caused a major security flaw.