Claude & Cursor Can Be Hijacked — Ransomware Now Takes 10 Hours ⚡
AI coding tools are now both a target and a weapon: attackers just found a sneaky way to hijack developer AI agents, while a separate ransomware crew used AI to blow through an entire corporate network in under a day. Here's what you need to know.
Your AI Coding Assistant Might Be Running Attacker Code
Security researchers discovered a sneaky trick that lets attackers hijack popular AI coding assistants like Claude Code, Cursor, and Codex. By planting a booby-trapped configuration file inside a shared code repository, an attacker can get the AI tool to silently run their commands the moment a developer opens the project — with that developer's own account permissions, no approval prompt, and no sandbox in the way. A few of the affected tools have already been patched, but several widely used ones are still exposed. If your team relies on AI coding assistants (and most engineering teams do now), this is worth flagging to them today.
Ransomware Attacks Just Got 30x Faster, Thanks to AI
A ransomware operator recently broke into and moved across an entire corporate network in under 10 hours — a job researchers estimate would normally take a skilled human team roughly two weeks. The difference was AI: the attackers used AI agents to handle the tedious work of navigating the network and escalating their access, letting a human "director" move at machine speed. It's a wake-up call for every business: the old assumption that defenders have days, or even weeks, to catch an intrusion in progress no longer holds. Detection and response times need to shrink to match.
Stay ahead of threats with GOCO Security at gocosecurity.com.
.jpg)
Comments
Post a Comment