Saturday, September 13, 2025
No Result
View All Result
Coins League
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Metaverse
  • Web3
  • Scam Alert
  • Regulations
  • Analysis
Marketcap
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Metaverse
  • Web3
  • Scam Alert
  • Regulations
  • Analysis
No Result
View All Result
Coins League
No Result
View All Result

Malicious Repos Can Trigger Auto Code Execution in Cursor

September 13, 2025
in Crypto Updates
Reading Time: 3 mins read
0 0
A A
0
Home Crypto Updates
Share on FacebookShare on TwitterShare on E Mail


Loved this text?

Share it with your folks!

Oasis Safety has recognized a vulnerability in Cursor, an AI-based code editor, that permits hidden code to run as quickly as a person opens a undertaking folder with none motion or warning.

The problem comes from a default setting in Cursor. A security characteristic referred to as Workspace Belief is disabled by default when this system is first put in. In consequence, sure activity information can start executing instructions instantly when a developer opens a folder.

If a person provides a dangerous activity to a undertaking and shares it on-line, these instructions will run as quickly as one other particular person opens the folder in Cursor.

Do you know?

Need to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer movies each week!

What’s SushiSwap? DEX & Sushi Token Animated Explainer

What is SushiSwap? DEX & Sushi Token Animated Explainer
What is SushiSwap? DEX & Sushi Token Animated Explainer

Cursor is constructed on high of Visible Studio Code, which additionally contains the Workspace Belief characteristic. This software is designed to guard builders from malicious code by blocking automated duties from unknown sources.

The vulnerability exploits the .vscode/duties.json file, which might include directions to run duties as quickly as a folder is opened. Attackers can place these directions in a shared undertaking.

In line with Erez Schwartz from Oasis Safety, this conduct can result in stolen credentials, modified information, or system entry. It additionally will increase the possibilities of provide chain assaults, the place malicious code spreads by way of instruments or initiatives utilized by many individuals.

To remain secure, customers ought to take a couple of steps. First, they need to allow Workspace Belief in Cursor to cease unknown duties from working robotically. Second, it’s suggested to open untrusted initiatives utilizing a distinct code editor, particularly the .vscode folder, earlier than utilizing Cursor.

On August 28, Anthropic warned that unhealthy actors are utilizing its chatbot Claude to assist perform on-line crimes. How? Learn the total story.



Source link

Tags: AutoCodeCursorExecutionMaliciousReposTrigger
Previous Post

Coinbase Files Legal Motion Against SEC Over Lost Texts From Ex-Chair Gary Gensler

Next Post

California Bill to Regulate AI Chatbots Nears Decision

Related Posts

Massachusetts Alleges Kalshi’s Event Contracts Are Illegal Sports Bets
Crypto Updates

Massachusetts Alleges Kalshi’s Event Contracts Are Illegal Sports Bets

September 13, 2025
Commerce Department, Chainlink, and Sei Collaborate: Macroeconomic Data Live On-Chain
Crypto Updates

Commerce Department, Chainlink, and Sei Collaborate: Macroeconomic Data Live On-Chain

September 13, 2025
Galaxy’s Solana Season Boost Fuels Hype – Why Snorter Token Could Ride Next
Crypto Updates

Galaxy’s Solana Season Boost Fuels Hype – Why Snorter Token Could Ride Next

September 13, 2025
Coinbase Files Legal Motion Against SEC Over Lost Texts From Ex-Chair Gary Gensler
Crypto Updates

Coinbase Files Legal Motion Against SEC Over Lost Texts From Ex-Chair Gary Gensler

September 13, 2025
From USDT to USAT: Tether Maps a Stateside Playbook
Crypto Updates

From USDT to USAT: Tether Maps a Stateside Playbook

September 12, 2025
Bitcoin und Gold: Die besten Wertspeicher der Gegenwart – und auch der Zukunft?
Crypto Updates

Bitcoin und Gold: Die besten Wertspeicher der Gegenwart – und auch der Zukunft?

September 12, 2025
Next Post
California Bill to Regulate AI Chatbots Nears Decision

California Bill to Regulate AI Chatbots Nears Decision

TopnotchCrypto Cloud Mining Offers BTC Holders High Passive Income

TopnotchCrypto Cloud Mining Offers BTC Holders High Passive Income

Bitcoin Treasury Holdings Cross $113 Billion, Who Are The Major Stakeholders?

Bitcoin Treasury Holdings Cross $113 Billion, Who Are The Major Stakeholders?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Twitter Instagram LinkedIn RSS Telegram
Coins League

Find the latest Bitcoin, Ethereum, blockchain, crypto, Business, Fintech News, interviews, and price analysis at Coins League

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Web3

SITEMAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2023 Coins League.
Coins League is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Metaverse
  • Web3
  • Scam Alert
  • Regulations
  • Analysis

Copyright © 2023 Coins League.
Coins League is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In