Showing only posts by Jessica Lyons. Show all posts.

Vibe coding tool Cursor's MCP implementation allows persistent code execution

Source

More evidence that AI expands the attack surface Check Point researchers uncovered a remote code execution bug in popular vibe-coding AI tool Cursor that could allow an attacker to poison developer environments by secretly modifying a previously approved Model Context Protocol (MCP) configuration, silently swapping it for a malicious …

Silent Push CEO on cybercrime takedowns: 'It's an ongoing cat-and-mouse game'

Source

Plus: why takedowns aren't in threat-intel analysts' best interest interview It started out small: One US financial services company wanted to stop unknown crooks from spoofing their trading app, tricking customers into giving the digital thieves their login credentials and account information, thus allowing them to drain their accounts …

FBI: Watch out for these signs Scattered Spider is spinning its web around your org

Source

New malware, even better social engineering chops The FBI and a host of international cyber and law enforcement agencies on Tuesday warned that Scattered Spider extortionists have changed their tactics and are now breaking into victims' networks using savvier social engineering techniques, searching for organizations' Snowflake database credentials, and …

« newer articles | page 4 | older articles »