ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories
Summary
This security bulletin covers multiple threats including a data theft campaign called City-Forum targeting unauthenticated guest access in Salesforce and ServiceNow systems using advanced, undocumented techniques; a data breach at ShipMonk (a Trezor shipping provider) exposing customer information; and a pre-trust code execution vulnerability in Cursor's CLI (command-line interface, a tool developers use to write code) agent that allowed malicious repositories to run commands before users could authorize them. The bulletin also describes Work Panel, an operator console used by threat actors to automate large-scale vishing campaigns (voice-based phishing attacks targeting identity verification systems).
Solution / Mitigation
Cursor released a patch three days after responsible disclosure on July 20, 2026, to fix the CLI pre-trust code execution vulnerability that allowed repositories to execute commands before workspace-trust verification.
Classification
Affected Vendors
Original source: https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html
First tracked: August 17, 2026 at 08:01 AM
Classified by LLM (prompt v3) · confidence: 72%