Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI, and Antigravity by exploiting files trusted host tools run.
AWS Kiro prompt injection flaw let hidden web page text rewrite the IDE's MCP configuration file and silently execute ...
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two ...
A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source ...
HalluSquatting exploits AI coding assistants that hallucinate fake repository names, letting attackers register those names ...
Cursor IDE zero-day vulnerability: AI security firm Mindgard spent seven months trying to report a Windows code-execution ...
The Check Point Research AI Security Report 2026, published by Check Point Software Technologies , describes a cybersecurity ...
EXCLUSIVE A jailbroken Google Gemini did 90 percent of the work in a credential- and cryptocurrency-stealing spree, including ...
GitHub Copilot jailbreak researchers at the Alan Turing Institute documented a technique that routes harmful requests through ...
With the ability to take control of distributed devices at scale, HalluSquatting has the potential to achieve various ...
Google was forced to cap Meta's use of its Gemini AI model after Mark Zuckerberg's company exceeded its computing capacity, sources familiar with the matter told The Financial Times. The incident ...