View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code

🚨 ACTIVE EXPLOITS & INCIDENTS

  • Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution — The Hacker News
    A critical flaw in Cursor on Windows allows automatic execution of a malicious git.exe binary placed in a project root without user interaction or warnings. This enables attackers to execute arbitrary code with the user’s privileges, accessing source code, SSH keys, and cloud tokens persistently while the project remains open. Immediate review of Cursor usage and environment hygiene is advised.

  • KFC Faces Possible Closures After Cyberattack on Japan's Nichirei — @metacurity / infosec.exchange
    A cyberattack on Nichirei, a major Japanese food supplier, is causing operational disruptions impacting KFC outlets in Japan. This incident highlights risks in food supply chain cybersecurity and potential cascading effects on retail operations. Monitoring for further details and supply chain risk mitigation is recommended.

🕵️ THREAT RESEARCH & DEEP DIVES

  • TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development — Palo Alto Unit 42
    Unit 42 analyzed TuxBot v3, an IoT botnet framework developed with large language model (LLM) assistance. The report details its cross-compiled binaries, command-and-control architecture, and embedded bugs, revealing how AI is accelerating malware sophistication in IoT environments. This signals a new wave of AI-augmented malware development requiring updated detection strategies.

  • OkoBot: New Sophisticated Malware Framework Targets Cryptocurrency Users — Securelist (Kaspersky)
    Kaspersky GReAT uncovered OkoBot, a complex malware framework targeting crypto users by stealing seed phrases and monitoring Chromium-based browsers. It deploys multiple payloads including the Rilide stealer and TookPS backdoor, indicating a multi-stage infection chain designed for persistent crypto asset theft. Crypto custodians and wallet providers should prioritize detection and mitigation of these tactics.

📋 VENDOR BULLETINS & ADVISORIES

  • White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative — SecurityWeek
    Following the June 2 AI-focused Executive Order, the White House introduced the Gold Eagle program to leverage AI for faster vulnerability coordination across government and private sectors. This initiative aims to accelerate patch deployment and threat intelligence sharing, signaling increased federal emphasis on AI-powered vulnerability management. Security teams should watch for integration opportunities and compliance impacts.

📰 LESSER-KNOWN / UNDER-REPORTED

  • UK Government Advises Public to Stockpile Food Against Potential Russian Cyberattacks — @metacurity / infosec.exchange
    UK’s No 10 Downing Street has issued guidance for citizens to stockpile food in anticipation of disruptive Russian cyberattacks targeting critical infrastructure. This unusual public advisory underscores growing geopolitical tensions and the potential for cyber operations to impact civilian supply chains. Security planners should consider implications for national resilience and crisis communications.

  • Lancet Commission: Misinformation Poses Greater Short-Term Threat Than Cybersecurity or Armed Conflict — @metacurity / infosec.exchange
    The Lancet Commission’s latest report ranks misinformation as a more immediate global threat than cyber insecurity, extreme weather, or state conflicts. This highlights the critical need for cybersecurity professionals to engage in combating disinformation campaigns that can indirectly undermine security postures and public trust.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check