CursorJacking
PulseAugur coverage of CursorJacking — every cluster mentioning CursorJacking across labs, papers, and developer communities, ranked by signal.
1 天有情绪数据
-
Cursor 代码编辑器易受浏览器扩展程序窃取 API 密钥的攻击
安全研究人员发现了一种名为“CursorJacking”的漏洞,影响了 Cursor 代码编辑器。该漏洞允许恶意浏览器扩展程序访问用户的 SQLite 数据库,其中可能包含敏感的 API 密钥。此问题凸显了授予浏览器扩展程序广泛权限可能带来的潜在风险,尤其是在它们与本地数据存储交互时。
-
Cursor and Claude Code targeted by new malware and vulnerabilities
A security vulnerability dubbed CursorJacking has been discovered, allowing browser extensions to access user API keys stored in the SQLite database of the AI-powered code editor Cursor. Separately, a new variant of the…
-
Google Gemini CLI hit with CVSS 10.0 RCE, breaking trust boundaries
A critical vulnerability with a CVSS score of 10.0 has been discovered in Google's Gemini CLI, allowing an attacker to execute arbitrary code by submitting a pull request that includes a malicious configuration file. Th…