DeFi Daily News
Monday, March 30, 2026
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home Cryptocurrency Altcoins

rewrite this title Malicious Repos Can Trigger Auto Code Execution in Cursor

Editor-In-Chief, BitDegree by Editor-In-Chief, BitDegree
September 12, 2025
in Altcoins
0 0
0
rewrite this title Malicious Repos Can Trigger Auto Code Execution in Cursor
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1000 words and keep HTML tags

Enjoyed this article?

Share it with your friends!

Oasis Security has identified a vulnerability in Cursor, an AI-based code editor, that allows hidden code to run as soon as a user opens a project folder without any action or warning.

The issue comes from a default setting in Cursor. A safety feature called Workspace Trust is disabled by default when the program is first installed. As a result, certain task files can begin executing commands immediately when a developer opens a folder.

If a user adds a harmful task to a project and shares it online, those commands will run as soon as another person opens the folder in Cursor.

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

How to Avoid Major Crypto Investment Risks? (Beginner-Friendly)

How to Avoid Major Crypto Investment Risks? (Beginner-Friendly)
How to Avoid Major Crypto Investment Risks? (Beginner-Friendly)

Cursor is built on top of Visual Studio Code, which also includes the Workspace Trust feature. This tool is designed to protect developers from malicious code by blocking automatic tasks from unknown sources.

The vulnerability exploits the .vscode/tasks.json file, which can contain instructions to run tasks as soon as a folder is opened. Attackers can place these instructions in a shared project.

According to Erez Schwartz from Oasis Security, this behavior can lead to stolen credentials, changed files, or system access. It also increases the chances of supply chain attacks, where malicious code spreads through tools or projects used by many people.

To stay safe, users should take a few steps. First, they should enable Workspace Trust in Cursor to stop unknown tasks from running automatically. Second, it is advised to open untrusted projects using a different code editor, especially the .vscode folder, before using Cursor.

On August 28, Anthropic warned that bad actors are using its chatbot Claude to help carry out online crimes. How? Read the full story.

and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website [http://defi-daily.com] and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: autoCodeCursorexecutionMaliciousReposrewritetitleTrigger
ShareTweetShare
Previous Post

rewrite this title Public Keys: Crypto IPOs Sizzle, Missing Gensler Texts Grizzle – Decrypt

Next Post

rewrite this title Dogecoin and BNB Rise as Bitcoin, Ethereum Hit Highest Prices This Month – Decrypt

Next Post
rewrite this title Dogecoin and BNB Rise as Bitcoin, Ethereum Hit Highest Prices This Month – Decrypt

rewrite this title Dogecoin and BNB Rise as Bitcoin, Ethereum Hit Highest Prices This Month - Decrypt

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
rewrite this title Google Unveils Flow: An All-in-One AI Video Editing Tool That Can Do It All!

rewrite this title Google Unveils Flow: An All-in-One AI Video Editing Tool That Can Do It All!

May 21, 2025
rewrite this title How to Get Top Solana Token Holders – Moralis APIs

rewrite this title How to Get Top Solana Token Holders – Moralis APIs

May 14, 2025
President Trump nominates Kevin Warsh for Fed chair, top takeaways from Apple’s big earnings beat

President Trump nominates Kevin Warsh for Fed chair, top takeaways from Apple’s big earnings beat

January 30, 2026
rewrite this title and make it good for SEO Hyperliquid Deep Dive: Understand HYPE and HLP Model

rewrite this title and make it good for SEO Hyperliquid Deep Dive: Understand HYPE and HLP Model

April 3, 2025
Vance, Trump’s VP Choice, Advocates for Stringent China Policy: Analyst Insights – Reuters

Vance, Trump’s VP Choice, Advocates for Stringent China Policy: Analyst Insights – Reuters

July 16, 2024
Vitalik Receives Criticism for Underestimating DeFi’s Contribution to Ethereum’s Expansion

Vitalik Receives Criticism for Underestimating DeFi’s Contribution to Ethereum’s Expansion

August 26, 2024
rewrite this title Bitcoin Breakdown Confirmed: Bearish Continuation Looms Despite Short-Term Bounce Setup

rewrite this title Bitcoin Breakdown Confirmed: Bearish Continuation Looms Despite Short-Term Bounce Setup

March 28, 2026
rewrite this title “I was just hanging on”: Michael McDowell admits he needed more than talent to stay afloat in NASCAR

rewrite this title “I was just hanging on”: Michael McDowell admits he needed more than talent to stay afloat in NASCAR

March 28, 2026
rewrite this title ‘Malcolm In The Middle’ Team On The Possibility Of A Full-Fledged Reboot: “A Whole New Set Of Characters And Circumstances That Are Ripe”

rewrite this title ‘Malcolm In The Middle’ Team On The Possibility Of A Full-Fledged Reboot: “A Whole New Set Of Characters And Circumstances That Are Ripe”

March 28, 2026
rewrite this title Today's NYT Strands Hints, Answer and Help for March 29 #756 – CNET

rewrite this title Today's NYT Strands Hints, Answer and Help for March 29 #756 – CNET

March 28, 2026
rewrite this title Arsenal Women 5-2 Tottenham Women: Alessia Russo hat-trick keeps Gunners in Women’s Super League title fight

rewrite this title Arsenal Women 5-2 Tottenham Women: Alessia Russo hat-trick keeps Gunners in Women’s Super League title fight

March 28, 2026
He Messed Up Bad, Now His Wife Doesn’t Trust Him

He Messed Up Bad, Now His Wife Doesn’t Trust Him

March 28, 2026
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.