CVE Tools
Back to feed
Exploited in the wild UNC6671 data-breach ai-ml

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

The Hacker News·By The Hacker News··14 min read
CVE Tools coverage

This weekly security roundup highlights a new AI attack vector called GhostJacking, which manipulates autonomous agents into executing arbitrary code and exfiltrating data via poisoned logs. Additionally, a pre-trust code execution flaw in the Cursor CLI coding agent has been resolved following responsible disclosure.

The bulletin also covers active in-the-wild exploitation by threat actor UNC6671 using the Work Panel platform for large-scale voice phishing campaigns against identity providers. Other notable updates include blockchain-based C2 obfuscation techniques like EtherHiding, industrial ransomware trends, and various supply chain compromises across cloud and software ecosystems.