CVE Tools

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

The Hacker NewsBy The Hacker News

Reported exploitedUNC6671

Our summary

This weekly security roundup highlights a new AI attack vector called GhostJacking, which manipulates autonomous agents into executing arbitrary code and exfiltrating data via poisoned logs. Additionally, a pre-trust code execution flaw in the Cursor CLI coding agent has been resolved following responsible disclosure.

The bulletin also covers active in-the-wild exploitation by threat actor UNC6671 using the Work Panel platform for large-scale voice phishing campaigns against identity providers. Other notable updates include blockchain-based C2 obfuscation techniques like EtherHiding, industrial ransomware trends, and various supply chain compromises across cloud and software ecosystems.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store