July 2, 2026
- Cato AI Labs disclosed DuneSlide — two critical zero-click prompt-injection flaws in Cursor (CVE-2026-50548, CVE-2026-50549, both ~9.8) that let a single crafted prompt escape the editor sandbox and run arbitrary commands on a developer's machine with no approval prompt. Fixed in Cursor 3.0. The Hacker News, Cato. · Vulnerabilities & Exploits
in Scattered Spider Suspect Grabbed at Helsinki Airport, Extradited to the US