Exploited in the wild UNC6671 data-breach ai-ml
ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories
CVE Tools coverage
This weekly security roundup highlights a new AI attack vector called GhostJacking, which manipulates autonomous agents into executing arbitrary code and exfiltrating data via poisoned logs. Additionally, a pre-trust code execution flaw in the Cursor CLI coding agent has been resolved following responsible disclosure.
The bulletin also covers active in-the-wild exploitation by threat actor UNC6671 using the Work Panel platform for large-scale voice phishing campaigns against identity providers. Other notable updates include blockchain-based C2 obfuscation techniques like EtherHiding, industrial ransomware trends, and various supply chain compromises across cloud and software ecosystems.