PANews reported on September 5th that, according to Cointelegraph, cybersecurity firm HiddenLayer reported that the AI programming tool Cursor suffers from a "CopyPasta License Attack" vulnerability. Hackers can trick the AI tool into injecting exploits into the codebase by hiding malicious instructions in the LICENSE.txt and README.md files. This tool, widely used by crypto exchanges such as Coinbase, exploits Markdown comments to hide prompt injections, causing the AI to automatically spread malicious payloads when editing files. Testing has also revealed that AI programming tools such as Windsurf, Kiro, and Aider are also vulnerable. The malicious code can create backdoors, steal sensitive data, or paralyze systems, and can be deeply hidden to avoid detection. When HiddenLayer creates tests for a repository containing a virus, Cursor automatically copies the prompt injection into the newly generated file. The company warns that this mechanism could have more serious consequences, including compromising critical files in development and production environments. In August, the Coinbase engineering team stated that Cursor was the preferred tool for most of its developers, and as of February, it had become the preferred tool for all engineers.PANews reported on September 5th that, according to Cointelegraph, cybersecurity firm HiddenLayer reported that the AI programming tool Cursor suffers from a "CopyPasta License Attack" vulnerability. Hackers can trick the AI tool into injecting exploits into the codebase by hiding malicious instructions in the LICENSE.txt and README.md files. This tool, widely used by crypto exchanges such as Coinbase, exploits Markdown comments to hide prompt injections, causing the AI to automatically spread malicious payloads when editing files. Testing has also revealed that AI programming tools such as Windsurf, Kiro, and Aider are also vulnerable. The malicious code can create backdoors, steal sensitive data, or paralyze systems, and can be deeply hidden to avoid detection. When HiddenLayer creates tests for a repository containing a virus, Cursor automatically copies the prompt injection into the newly generated file. The company warns that this mechanism could have more serious consequences, including compromising critical files in development and production environments. In August, the Coinbase engineering team stated that Cursor was the preferred tool for most of its developers, and as of February, it had become the preferred tool for all engineers.

Coinbase's preferred AI programming tool, Cursor, is at risk of being hijacked by a new virus.

2025/09/05 12:45
1 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo crypto.news@mexc.com.

PANews reported on September 5th that, according to Cointelegraph, cybersecurity firm HiddenLayer reported that the AI programming tool Cursor suffers from a "CopyPasta License Attack" vulnerability. Hackers can trick the AI tool into injecting exploits into the codebase by hiding malicious instructions in the LICENSE.txt and README.md files. This tool, widely used by crypto exchanges such as Coinbase, exploits Markdown comments to hide prompt injections, causing the AI to automatically spread malicious payloads when editing files. Testing has also revealed that AI programming tools such as Windsurf, Kiro, and Aider are also vulnerable. The malicious code can create backdoors, steal sensitive data, or paralyze systems, and can be deeply hidden to avoid detection.

When HiddenLayer creates tests for a repository containing a virus, Cursor automatically copies the prompt injection into the newly generated file. The company warns that this mechanism could have more serious consequences, including compromising critical files in development and production environments. In August, the Coinbase engineering team stated that Cursor was the preferred tool for most of its developers, and as of February, it had become the preferred tool for all engineers.

Opportunità di mercato
Logo Prompt
Valore Prompt (PROMPT)
$0.03202
$0.03202$0.03202
+0.85%
USD
Grafico dei prezzi in tempo reale di Prompt (PROMPT)
Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta crypto.news@mexc.com per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

$30,000 in PRL + 15,000 USDT

$30,000 in PRL + 15,000 USDT$30,000 in PRL + 15,000 USDT

Deposit & trade PRL to boost your rewards!