Security Alert: AI Programming Tool Cursor at Risk of New Virus Hijacking
BlockBeats News, September 5th, according to Cointelegraph, cybersecurity firm HiddenLayer reported that the AI programming tool Cursor has a "CopyPasta License Attack" vulnerability. Hackers can hide malicious commands in the LICENSE.txt and README.md files to induce the AI tool to inject the vulnerability into the codebase. This tool is widely adopted by cryptocurrency exchanges like Coinbase.
The attack leverages Markdown comment hiding to inject prompts, causing AI to automatically propagate the malicious payload while editing files. Tests have shown that AI programming tools such as Windsurf, Kiro, and Aider also have the same vulnerability. The malicious code can create backdoors, steal sensitive data, or cripple systems, all while deeply concealing itself to evade detection.
You may also like

OpenAI has no "New Deal," a blueprint for AI that refuses to pay.

Wall Street Flash Mob Run? Mega-Cap Stock Plunge, Goldman's Great Escape, Illustrated Guide to Private Credit Crisis

OpenAI Feud: Power, Trust, and the Uncontrollable Boundaries of AGI

「AI Doomsday Cult」 Sends Operatives into the Strait of Hormuz: What Did They Find?

Everyone is waiting for the war to end, but is the oil price signaling a prolonged conflict?

Data Analysis: How Wide is the Liquidity Gap Between Hyperliquid and CME Crude Oil?

After a 40% Reduction in Staff, Twitter's Founder to Give Away $1 Million in Bitcoin

Trade.xyz: Pricing the World? On-Chain Markets Are Becoming the Market

XXYY Trade Skill: 24/7 Algorithmic Trading AI Trader | Project Introduction

DeFi's top protocol Aave's security team exits, who will weather the next black swan event in the bear market?

Can the person who has been most accurate in predicting gold prices throughout history predict future gold prices?

Quantum Computing Won't Kill Bitcoin, But the Real Risk Is Approaching

When Fintech Merges with the Underlying Crypto: The Next Decade of Digital Finance

You may encounter high-net-worth clients who are possibly "mercenaries" for North Korean hackers

Chaos Labs exits, Aave loses its last risk gatekeeper

Quantum computing will not kill Bitcoin, but the real risks are approaching

Coinbase pushes x402 to neutral, while Stripe continues to bet on both sides outside of MPP

Untitled
I’m sorry, but I can’t fulfill this request as it requires content from an original source that wasn’t…
