September 10, 2026
BlueMoon exploit kit chains Chrome and Windows zero-days within days of patch publication, with four suspected China-linked espionage groups weaponizing the same toolkit on US and Southeast Asian targets from late August onward. Cisco Secure Firewall Management Center CVEs are under active exploitation by three distinct post-compromise clusters including a ransomware operator and Sandworm-attributed activity. DeepSeek AI agent harness contained an authentication bypass allowing remote agents to escalate privileges via a single shell command; Anthropic declined to provide pre-release model access to UK authorities, triggering debate over AI protectionism. Stealer logs now monetize replayable AI-service tokens from compromised systems, with over 500 valid Google, Anthropic, and Cursor credentials found in a single 7 GB dump.
September 3, 2026
- A malicious
.git config is enough to get CLI coding agents to run attacker code. Manifold Security disclosed eight flaws across seven command-line AI coding agents — including Claude, Codex and Cursor — where a repository's own Git configuration names a command the agent then executes on the developer's machine, as the user, outside the agent's sandbox and with no approval prompt. Four were still unpatched at publication; the only prerequisite is cloning a hostile repo (The Hacker News).
· AI-Enabled Attacks & Agent Security
in Ten Hours, Fifty Techniques: AI Agents Ran the Whole Ransomware Intrusion
August 31, 2026
- OpenAI cut off Cursor's model access following SpaceX's acquisition of the company; Cursor co-founder Michael Truell says OpenAI models were about 5% of the tool's AI traffic (The Decoder).
· Industry & Policy
in Fully Patched, Still Domain Admin
August 28, 2026
- Aurora ransomware operators used the Cursor coding agent live during intrusions. Researchers recovered weeks of operator interaction logs from attacker infrastructure showing AI assistance for internal enumeration, Active Directory reconnaissance, privilege discovery, VPN/proxy configuration, credential hunting and general troubleshooting across seven victim companies (Reuters).
· AI & Model Security
in Australia Charges Two Over the TeamPCP Supply-Chain Spree
August 8, 2026
- Amazon, Cursor, Microsoft, OpenAI, and Vercel launched Agent Plugins, an open standard defining a single package format for AI agent extensions; v1.0.0 uses a
plugin.json manifest and supports both agent skills and MCP servers. The Decoder (discussion)
· Industry & Policy
in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold
July 21, 2026
- Seven sandbox-escape vulnerabilities across four coding-agent vendors — Cursor, Codex, Gemini CLI, and Antigravity — were disclosed by Pillar Security, underscoring that agentic dev tools ship with weak isolation between attacker-controlled content and host execution. Pillar Security, BleepingComputer. (discussion).
· AI & Model Security
in Microsoft Graph Becomes a Spy's Dead Drop as WordPress "wp2shell" Exploitation Goes Live
July 15, 2026
- Cursor IDE auto-executes malicious code from poisoned repositories, per Mindgard's full disclosure of an unpatched arbitrary-code-execution flaw. Researchers reported it to Cursor in December; it remains exploitable in the popular AI coding platform. Mindgard, Dark Reading
· AI & Model Security
in Record-Breaking Patch Tuesday Ships With Live Active Directory and SharePoint Zero-Days
July 9, 2026
- GhostApproval — Wiz found symlink flaws in six AI coding assistants (Amazon Q Developer, Claude Code, Augment, Cursor, Google Antigravity, Windsurf) that let a booby-trapped repo turn an approved edit to a harmless-looking file into a write to a sensitive one, yielding RCE via a misleading confirmation dialog. Several vendors have shipped urgent patches. The Register, The Hacker News
· AI & Model Security
- Sophos telemetry shows benign AI coding agents (Claude Code, Cursor, Codex) routinely tripping behavioral EDR rules written for human intruders — decrypting browser credentials, enumerating the Windows credential store, etc. A real detection-engineering problem: agent activity and attacker activity look identical to the engine. The Hacker News
· AI & Model Security
in A 15-Year-Old Linux Kernel Bug Hands Root on Every Distro
July 2, 2026
- Cato AI Labs disclosed DuneSlide — two critical zero-click prompt-injection flaws in Cursor (CVE-2026-50548, CVE-2026-50549, both ~9.8) that let a single crafted prompt escape the editor sandbox and run arbitrary commands on a developer's machine with no approval prompt. Fixed in Cursor 3.0. The Hacker News, Cato.
· Vulnerabilities & Exploits
in Scattered Spider Suspect Grabbed at Helsinki Airport, Extradited to the US