HiddenLayer: The AI programming tool Cursor used by exchanges like Coinbase has vulnerabilities.

robot
Abstract generation in progress

Techub News reports that according to Cointelegraph, cybersecurity company HiddenLayer has reported a vulnerability in the AI programming tool Cursor known as the “CopyPasta License Attack.” Hackers can inject vulnerabilities into the codebase by hiding malicious instructions in the LICENSE.txt and README.md files, enticing the AI tool to do so. This tool is widely adopted by crypto assets exchanges such as Coinbase. The attack uses Markdown comments to hide prompt injections, causing the AI to automatically propagate the malicious payload while editing the files. Tests show that AI programming tools like Windsurf, Kiro, and Aider also have vulnerabilities. The malicious code can create backdoors, steal sensitive data, or incapacitate systems, and can deeply hide to avoid detection.

TXT-0,62%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • بالعربية
  • Português (Brasil)
  • 简体中文
  • English
  • Español
  • Français (Afrique)
  • Bahasa Indonesia
  • 日本語
  • Português (Portugal)
  • Русский
  • 繁體中文
  • Українська
  • Tiếng Việt