{"data":{"id":"fc95c77a-b620-4e03-b066-6814a2942c48","title":"ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories","summary":"This security bulletin covers multiple threats including a data theft campaign called City-Forum targeting unauthenticated guest access in Salesforce and ServiceNow systems using advanced, undocumented techniques; a data breach at ShipMonk (a Trezor shipping provider) exposing customer information; and a pre-trust code execution vulnerability in Cursor's CLI (command-line interface, a tool developers use to write code) agent that allowed malicious repositories to run commands before users could authorize them. The bulletin also describes Work Panel, an operator console used by threat actors to automate large-scale vishing campaigns (voice-based phishing attacks targeting identity verification systems).","solution":"Cursor released a patch three days after responsible disclosure on July 20, 2026, to fix the CLI pre-trust code execution vulnerability that allowed repositories to execute commands before workspace-trust verification.","labels":["security"],"sourceUrl":"https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html","publishedAt":"2026-08-13T18:17:10.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":[],"issueType":"news","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Cursor","Okta"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-13T18:17:10.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.72,"researchCategory":null,"atlasIds":null}}