Visualização de leitura

Cursor customers will lose access to OpenAI coding models in November

OpenAI will stop AI coding platform Cursor from accessing its models from November 12, following the acquisition of Cursor parent Anysphere by Elon Musk‘s SpaceX.

“Today, we notified SpaceX that we intend to wind down our contract providing OpenAI models to Cursor, with a proposed shutoff date of November 12, 2026,” the company wrote in a blog post.

That shutoff, the company added, was based on its concerns that SpaceX will not use its technology in accordance with its terms of service, citing what it described as a history of Musk’s companies violating contracts: “After Musk acquired Twitter, now part of SpaceX, the company broke⁠ the terms of our contract (alongside many others). Under oath earlier this year, Musk admitted⁠ that xAI, now also part of SpaceX, had violated OpenAI’s terms of service (terms which are similar to xAI’s own),” the company wrote.

OpenAI and Musk remain locked in a broader legal dispute, with Musk having sued OpenAI over its transition from a nonprofit-controlled organization to a for-profit structure and OpenAI countering with allegations over Musk’s conduct and competing AI ventures.

Enterprises and developers using OpenAI models within Cursor now have about 10 weeks to transition to other AI models within Cursor, or choose a new coding platform.

Swapping problem

That may not be easy.

While the 10-week timeframe might be enough to assess the impact and decide a path forward, it will not be a trivial operation, said Abhishek Satapathy, principal analyst at Avasant.

Even for those just swapping models and staying with Cursor, there will be effort required to validate the replacement against development workflows currently running on OpenAI’s models, Satapathy said.

“This includes repository-level coding, debugging, refactoring, test case generation, multi-file changes and tasks where an agent has to inspect a codebase, make a sequence of changes, run tests and correct its own errors,” he said.

The need for validation stems from differences in how AI models handle coding, reasoning, tool use and instructions.

Developers may find that prompts or agent instructions that work well with OpenAI models produce different results with another model, requiring enterprises to retune prompts and evaluations, said Manoj Chandra Jha, principal analyst at Nord-IQ Research.

That recalibration could translate into a short-term productivity dip as development teams rework prompts and workflows and adjust to how the replacement model behaves, echoed Bhupendra Chopra, chief revenue officer at IT consulting firm Kanerika.

For enterprises considering a move away from Cursor, the transition becomes more complex, primarily because swapping coding platforms would require retraining developers, rebuilding integrations and agent configurations, and repeating security and governance reviews that not only require time but also adds costs, Satapathy said.

Broader risks of AI vendor dependence

The added complexity of changing platforms points to a broader issue for enterprises: their dependence on AI model providers and the commercial relationships that determine where those models can be used.

“Enterprises can no longer assume that a model available through an AI coding platform today will always remain available. Acquisitions, contracts, competition or regulation can change this,” said Pareekh Jain, principal analyst at Pareekh Consulting.

“Enterprises should therefore support multiple models, regularly test alternatives and avoid making important workflows too dependent on one model,” Jain added.

Similar principles should apply to the coding platforms as well, according to Satapathy.

“Enterprises should consider whether prompts, agent configurations, evaluation methods and tool integrations can be reused when the underlying model changes,” Satapathy said.

There are broader risks for the vendors too, especially OpenAI.

While Cursor appears better positioned to retain customers because enterprises can continue using the platform with other models, particularly with Anthropic’s pledged support, OpenAI risks losing developer usage as customers move to alternatives such as Claude without having to change their coding environment, Satapathy said.

This article first appeared on InfoWorld.

Gemini Notebook Adopts Dynamic Quota System

Google transitions Gemini Notebook to a dynamic quota system based on computational load, introducing a strict 5-hour rolling limit for users.

Related Posts:

The post Gemini Notebook Adopts Dynamic Quota System appeared first on Daily CyberSecurity.

Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows

At Black Hat USA 2026, Novee found GitHub workflow flaws in Claude Code, Gemini CLI and Codex that enabled RCE, credential theft and agent control in pipelines.

ClickFix Attacks Drive UAC-0145 Cyber Campaigns, CERT-UA Warns

ClickFix Attacks

The ClickFix attacks technique has become a key initial access method for the UAC-0145 cyber threat cluster, according to a new report from Ukraine's Computer Emergency Response Team (CERT-UA). The agency said the threat group, also tracked as Sandworm, APT44, Seashell Blizzard, and a subcluster of UAC-0002, has shifted its tactics during 2026, increasingly relying on fake CAPTCHA prompts and social engineering to compromise systems.

CERT-UA said it has worked with Ukrainian cybersecurity agencies for several years to investigate the activities of UAC-0145. While the group previously relied on infected software installers distributed through torrent websites, recent campaigns have increasingly used ClickFix to trick users into executing malicious PowerShell commands.

ClickFix Attacks Emerging as Primary Initial Access Vector

According to CERT-UA, infections recorded during the spring and summer of 2026 frequently began when victims visited compromised websites displaying fake CAPTCHA pages. Users were instructed to copy and execute PowerShell commands in their terminal, a phishing technique commonly referred to as ClickFix.

The downloaded commands were designed to retrieve malicious files such as GHETTOVIBE, a Visual Basic Script (VBS) that establishes persistence by placing itself in the Windows Startup directory.

Once executed, attackers could deploy SCOUTCURL, a PowerShell reconnaissance tool capable of collecting information about the compromised system, including device specifications, installed software, browser data, and local files before exfiltrating the information.

CERT-UA also observed malware loaders including FLUIDLEECH, disguised as antivirus software, and LOADLOOP being used during these campaigns.

Backdoors and Data Theft Tools Widely Deployed

The report noted that attackers continue using malware families such as KALAMBUR, SUMBUR, and TAMBUR after gaining access to victim systems.

To maintain remote access, the group relied on legitimate utilities including OpenSSH and Tor, forwarding local network ports such as 445, 3389, and 22 to attacker-controlled infrastructure.

CERT-UA also found malware designed to steal messaging data from Signal and WhatsApp, with stolen information reportedly exfiltrated using RSYNC.

On infected systems examined during cyber defense operations, investigators additionally identified FREAKYPOLL, a Python-based backdoor distributed as compiled bytecode (.pyc), providing attackers with persistent unauthorized access.

Compromised Websites Used to Deliver Fake CAPTCHA Pages

During June and July 2026, CERT-UA analyzed more than ten compromised websites involved in ClickFix attacks.

Investigators found attackers using both the Cloaking.House service and custom malware called SMARTAXE to dynamically modify legitimate webpages. SMARTAXE retrieves remote domains from blockchain smart contracts through Ethereum's eth_call function before displaying fake CAPTCHA pages or redirecting visitors to malicious content.

CERT-UA warned that any website used in these attacks should be considered compromised, potentially through vulnerable content management systems (CMS), stolen credentials, web shells, malicious plugins, modified website scripts, or server-side backdoors.

The agency urged website administrators and hosting providers to strengthen website security and respond quickly to incident reports.

Android Malware Also Part of UAC-0145 Operations

The report also highlighted growing use of Android malware distributed through messaging applications.

Attackers were observed sharing APK files disguised as security or antivirus tools. One such malware family, tracked as COWARDDUCK, functions as a full-featured Android backdoor capable of collecting device information, contacts, files, and real-time geolocation.

The malware targets files from directories including DCIM, Documents, Downloads, Pictures, and Alarms while searching for formats such as DOCX, XLSX, PPTX, ZIP, RAR, JSON, and OVPN files.

According to CERT-UA, COWARDDUCK uploads stolen files through the Dropbox API while receiving commands from legitimate services including Steam Community and StockMemory domains through proxy infrastructure.

Microsoft Sees Global Rise in ClickFix Campaigns

Microsoft Threat Intelligence and Microsoft Defender Experts also reported that ClickFix campaigns have increased significantly since early 2024, targeting thousands of enterprise and consumer devices globally each day.

Microsoft said the technique commonly delivers malware such as Lumma Stealer by persuading users to copy and execute commands through Windows Run, Windows Terminal, or Windows PowerShell. The campaigns are often combined with phishing, malvertising, and drive-by compromise techniques that imitate trusted brands.

Because ClickFix attacks rely on user interaction rather than exploiting software vulnerabilities directly, Microsoft recommends organizations strengthen user awareness and apply security policies that restrict unnecessary use of command execution tools.

WhatsApp Malware Campaign Hijacks Trust, Installs Legitimate Admin Tools

WhatsApp accounts were hijacked to spread fake debt notices that install remote access software, giving attackers control of victims’ PCs.

Kaspersky published a technical analysis this week of an active malware campaign that spreads through WhatsApp messages and ends with a remote management tool silently installed on the victim’s machine. The campaign is still running as of June 22, 2026, and has hit users across Malaysia, Brazil, India, Mexico, Singapore, the UK, Spain, Taiwan, Australia, Russia, and Vietnam. Eighty percent of confirmed victims are in Malaysia.

“The threat actor uses deceptive file names masquerading as business and financial documents to persuade recipients to download and execute the attachment.” reads the report published by Kaspersky. “Once executed, the VBScript initiates a multi-stage infection chain that ultimately results in the installation of legitimate Remote Monitoring and Management (RMM) software, enabling remote access to the victim’s system.”

The files arrive with names like “Statement of Debt(30K).vbs” or “Outstanding Payment List.vbs,” localized into Portuguese, French, German, and Malay for different targets. Someone put real effort into this. File names in six languages are not the work of someone running a quick side hustle.

The messages come from contacts the victim already knows, which is the whole point.

“Based on evidence collected from multiple victims through social media reports and submitted samples, we can conclude that the threat actor had gained access to several WhatsApp accounts and used them to distribute the malicious VBScript files to contacts on the compromised users’ contact lists.” continues Kaspersky. “At the time of writing, the exact method used to compromise these WhatsApp accounts remains unknown.”

The messages contained only the attachment with no accompanying text, and one compromised account sent the same file to multiple contacts at once. How those WhatsApp accounts were taken over in the first place is still unknown.

The infection runs in three stages. The first VBScript creates a hidden working directory under C:\Users\Public\Documents\ and downloads two more scripts from attacker-controlled servers. The scripts use heavy obfuscation including randomized variable names, string concatenation built character by character, and chunks of junk content, and they even embed fake Windows Update comments written in Chinese to make the code look like a legitimate Microsoft component.

The second stage scripts handle two things separately: one tries to disable Windows’ UAC prompt by modifying a registry key so administrative actions stop asking for confirmation, and the other downloads a ZIP archive containing the actual payload. The UAC-modification script runs the registry change in a loop with short delays between attempts, trying repeatedly until it either succeeds or the user dismisses enough prompts to give up.

What’s inside that ZIP is a pre-configured ManageEngine Endpoint Central deployment package, a legitimate enterprise remote management tool. The setup script installs it silently so the user sees nothing, then connects the newly installed agent to attacker-controlled management servers. One of those server IPs, 202.61.160.201, had previously appeared in infrastructure linked to ValleyRAT and Gh0st RAT activity.

“Although the overlap raises the possibility of the VBS campaign being linked to the operator of these known malware families, the available evidence is insufficient to confidently attribute the campaign to a known threat actor.”

Kaspersky assesses with low confidence that the operator is Chinese-speaking, based on the simplified Chinese comments embedded throughout the scripts.

The practical takeaway is simple: VBS, VBE, BAT, CMD, JS, and PS1 files don’t belong in a WhatsApp chat, even from a contact you trust. If someone sends you a financial document through a messaging app with no accompanying message, that’s not how accountants work.

“Users should be cautious when receiving unexpected attachments through WhatsApp, even when they appear to originate from known contacts.” concludes the report. “Script and executable file types such as VBS, VBE, EXE, BAT, CMD, JS, and PS1 should not be opened unless their legitimacy has been independently verified.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, WhatsApp)

NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands

Agentic AI Deployment

The UK’s National Cyber Security Centre (NCSC) has warned organizations to take a measured approach toward adopting agentic AI, highlighting the growing cyber and operational risks associated with highly autonomous AI systems. In a new guidance document co-authored with international partners, the NCSC said businesses should avoid rushing into large-scale deployments of agentic AI tools without understanding the security implications. The guidance recommends starting with low-risk use cases, limiting system privileges, and maintaining strong human oversight throughout deployment. The advisory comes as organizations increasingly experiment with AI systems capable of making decisions, accessing tools, and carrying out actions with limited human involvement.

What Is Agentic AI?

Unlike traditional generative AI systems that primarily create text, images, or predictions, agentic AI systems are designed to independently pursue goals. These systems can access data sources, remember context, make decisions, interact with software tools, and even create sub-agents to complete tasks. According to the NCSC, this added autonomy is what makes agentic AI useful for areas such as cyber defense, workflow automation, and operational efficiency. However, it also introduces a wider attack surface and increases the difficulty of monitoring system behavior. The agency noted that many security risks linked to AI are not entirely new. Concerns around access control, supply chain security, monitoring, and incident response already exist in traditional IT systems. Agentic AI systems also inherit existing large language model risks, including prompt injection and jailbreaking attacks. However, the NCSC warned that the autonomy of agentic AI systems could amplify these issues, especially if organizations deploy them without proper safeguards.

Why Agentic AI Raises Security Risks

The guidance outlines several risks tied to agentic AI deployments. One of the main concerns is broader access to systems and sensitive data. AI agents may interact with external tools, APIs, or databases in ways that traditional AI applications do not. The NCSC also highlighted the possibility of unpredictable behavior. Since AI agents interpret goals autonomously, they may take actions that differ from human expectations or exceed their intended scope. Another challenge involves visibility and oversight. Autonomous systems can operate at speeds that make meaningful human review difficult, particularly in enterprise environments where multiple systems and workflows are interconnected. The guidance further noted that explaining the behavior of agentic AI systems can be more difficult than understanding conventional AI models. The combination of decision-making, tool usage, and autonomous actions creates additional complexity during incident investigations or compliance reviews.

NCSC Calls for Incremental Agentic AI Deployment

To reduce risks, the NCSC urged organizations to adopt agentic AI gradually instead of deploying it across critical systems from the outset. The guidance recommends tightly controlled pilot deployments focused on clearly defined, low-risk tasks. Organizations are also encouraged to assess whether AI is genuinely necessary before integrating autonomous agents into existing workflows. “If you cannot understand, monitor or contain an agent’s actions, it is not ready for deployment,” the guidance stated. The agency stressed that organizations should never grant unrestricted access to sensitive data or critical infrastructure. Maintaining visibility into AI system behavior and preserving meaningful human control were identified as key requirements for safe deployment.

Human Accountability Remains Essential

Despite the growing capabilities of autonomous AI systems, the NCSC emphasized that humans remain fully accountable for how these technologies are used. The guidance states that organizations should clearly define who is responsible for approving AI access, monitoring system behavior, reviewing incidents, and shutting systems down when necessary. Security teams were also advised to integrate agentic AI risk management into existing cybersecurity and governance frameworks instead of treating AI security as a separate process. Recommended practices include applying least-privilege access controls, limiting system scope, avoiding long-lived credentials, monitoring unusual behavior, and planning for incidents involving AI misuse or loss of control.

Path Forward

While warning about the risks, the NCSC acknowledged that agentic AI could deliver significant operational benefits, particularly for repetitive and low-risk tasks. The agency said organizations should focus on responsible and scalable adoption strategies built around existing cybersecurity practices and strong governance controls. The guidance ultimately encourages businesses to move carefully, test systems incrementally, and prepare for potential failures before expanding the role of autonomous AI systems across enterprise environments.

Shadow AI Is Growing in Silence While Enterprise Security Falls Behind

Shadow AI Is Growing in Silence

By Niall Browne, CEO and Founder, AIBound
Shadow AI is accelerating alongside artificial intelligence (AI) adoption at a pace that has outgrown most enterprise governance models. Artificial intelligence (AI) adoption is accelerating at a pace that has outgrown most enterprise governance models. According to the World Economic Forum, 87% of organizations report that AI-related vulnerabilities are now the fastest-growing cyber risk. Part of this surfaces with  employees increasingly deploying autonomous AI agents that connect to MCP servers and external AI that security teams have never assessed, quietly piping sensitive corporate data into systems no one in IT has ever audited — and no one in the C-suite knows exist. This increase in Shadow AI is creating systemic enterprise risk that can lead to unforeseen costs. Compliance frameworks like the Artificial Intelligence Act of the European Union (EU AI Act) take full effect this year introducing penalties up to 7% of global annual revenue for unmanaged AI. As regulatory frameworks begin to align with the realities of increased AI adoption, enterprises need to account for decentralized AI usage that operates outside traditional controls. This requires software that allows greater visibility, organization, and control into how AI is used and tracked across environments.

Shadow AI Is Creating a New Enterprise Attack Surface

The traditional security stack was built for a world that no longer exists — one with known assets, centralized systems, and software that asked permission before it ran. As new tools are introduced independently, usage levels evolve quickly without system checks or visibility into how these tools interact with sensitive data. Research indicates that 75% of CISOs have discovered unsanctioned GenAI tools in their environments, and only 5% feel confident they could contain compromised AI agents. Because of how easy these platforms are to access and require little onboarding, adoption is happening across teams at a rapid rate without IT involvement. Other security issues lie with employees integrating workflows with personal AI agents. These deployments allow sensitive information to be leaked or directly inputted into agents without security knowledge. Without a system in place for organizations to continuously track and evaluate how AI is being used across their enterprise systems, CISOs are left without visibility of their attack surfaces. The result is a slow-motion breach: data leaking, compliance crumbling, and governance reduced to a slide deck nobody enforces. Recurring data leaks and breaches via AI reveal the need for solutions that address this gap. Popular AI agents like ChatGPT for example, revealed a ‘ShadowLeak’ vulnerability that allowed sensitive email data to be breached through a zero-click attack. Other short lived features that rolled out last year allowed conversation sharing, leaving employee info, internal corporate strategies, and other sensitive data to be shared and indexed by search engines. Although this option only was available for a day, it was estimated that over 100,000 private chats were affected and able to be viewed with a simple search, allowing any sensitive information inputted to be publicly accessible. Other recent breaches include a Microsoft 365 Copilot bug allowing AI assistants to summarize emails labeled confidential, bypassing data loss prevention policies set up by organizations. Microsoft confirmed that a code issue allowed confidential emails data to be accessed despite organizational securities put in place. These agents are live and operational with local access to files, systems, commands, and APIs capable of executing tasks and retrieving data without clear oversight control. As AI usage continues to expand at accelerating rates, organizations need a way to better understand how these tools are used across their environments. No CISO has ever defended a perimeter they couldn't see. Shadow AI is the new perimeter — and most security teams are flying blind. Without a comprehensive inventory and control of AI usage, security teams are unable to accurately assess risks and enforce policy to maintain compliance.

Shadow AI Demands Continuous Visibility and Independent AI Control Planes

This is where adoption of independent AI Control Planes becomes vital. Independent AI Control Planes provides a way to continuously identify and assess AI activity giving security teams the visibility needed to manage emerging risks. It enables organization and categorization of AI usage across enterprises without relying on the manual entry and tracking that existing platforms demand — work no security team in a fast-moving environment can realistically keep up with. It’s undeniable: Shadow AI is not a future problem — it is already running inside your enterprise, on assets you don't own, through agents you never approved, touching data you are responsible for protecting. Every day without continuous, autonomous AI discovery is a day your attack surface grows faster than your governance can chase it. Regulators won't wait. Attackers already aren't. The CISOs who win the next 24 months will be the ones who stop pretending policy equals control and start operating on a simple truth: if you can't see it, you can't secure it — and right now, most of AI is invisible.

Disclaimer: The views and opinions expressed in this guest article are solely those of the author and do not necessarily reflect the official policy or position of The Cyber Express. The information shared is intended for industry discussion and awareness purposes only.

NCSC Warns Organisations to Act Fast as Hidden Software Flaws Surface

vulnerability patch wave

Organisations worldwide are being urged to prepare for a vulnerability patch wave, as security experts warn that advances in artificial intelligence (AI) could rapidly expose long-standing weaknesses across software systems. The warning comes from National Cyber Security Centre (NCSC), which says businesses must act now to strengthen their environments before a surge of critical updates arrives. In a blog, Chief Technology Officer Ollie Whitehouse highlighted that years of accumulated technical debt are now becoming a major cybersecurity risk. Technical debt refers to unresolved flaws and compromises in software that arise when organisations prioritise speed or short-term delivery over long-term resilience. According to Whitehouse, artificial intelligence is accelerating the problem. Skilled attackers are increasingly able to use AI tools to identify and exploit vulnerabilities at scale, forcing what the NCSC describes as a “correction” across the technology ecosystem. This is expected to trigger a vulnerability patch wave, with a high volume of security updates affecting open source, commercial, proprietary, and software-as-a-service platforms.

Prioritising External Attack Surfaces

As part of preparing for the vulnerability patch wave, the NCSC advises organisations to first focus on their external attack surfaces. Internet-facing systems, cloud services, and exposed infrastructure present the highest risk when new vulnerabilities are disclosed. The guidance recommends a perimeter-first approach. Organisations should secure outward-facing technologies before moving deeper into internal systems. This reduces the likelihood that attackers can exploit newly discovered weaknesses during the vulnerability patch wave. Where resources are limited, priority should be given to patching systems that are directly exposed to the internet. Critical security infrastructure should follow next. However, the NCSC cautions that patching alone will not solve every issue. Legacy and end-of-life systems remain a major concern. Many of these technologies no longer receive security updates, leaving organisations vulnerable even during a vulnerability patch wave. In such cases, businesses may need to replace outdated systems or bring them back into supported environments, especially if they are externally accessible.

Preparing for Faster and Large-scale Patching

The expected vulnerability patch wave will require organisations to rethink how they manage updates. The NCSC is urging businesses to prepare for faster, more frequent, and large-scale deployment of security patches, including across supply chains. Several key measures have been recommended:
  • Enable automatic updates wherever possible to reduce operational burden
  • Adopt secure “hot patching” to apply fixes without service disruption
  • Ensure internal processes support rapid and large-scale updates
  • Use risk-based prioritisation models such as Stakeholder Specific Vulnerability Categorisation (SSVC)
Whitehouse noted that organisations must be ready to accelerate patching timelines when critical vulnerabilities are actively exploited, particularly those affecting internet-facing systems. At the core of this approach is an “update by default” policy. This means applying software updates as quickly as possible, ideally through automated processes. While this may not always be feasible for safety-critical or operational technology systems, the NCSC says it should form the foundation of modern vulnerability management strategies.

Beyond Vulnerability Patch Wave: Addressing Systemic Risks

The NCSC emphasises that the vulnerability patch wave is only part of a broader cybersecurity challenge. Patching addresses immediate risks, but it does not eliminate the underlying causes of technical debt. Technology vendors are being encouraged to build more secure systems from the outset. This includes adopting memory safety and containment technologies such as CHERI, which can reduce the likelihood of exploitable vulnerabilities. For organisations operating critical services, strengthening cybersecurity fundamentals is equally important. Frameworks such as Cyber Essentials and sector-specific resilience models can help reduce the impact of breaches and improve overall security posture. Additional guidance has also been issued for high-risk environments, covering areas such as privileged access workstations, cross-domain security architecture, and threat detection through observability and proactive hunting.

Organisations Urged to Act Now

The NCSC has made it clear that preparation cannot be delayed. The anticipated vulnerability patch wave is expected to impact organisations of all sizes and sectors. Businesses are advised to review their vulnerability management processes, assess their exposure, and ensure their supply chains are also ready to respond. Larger organisations, in particular, are encouraged to seek assurance from both commercial and open-source partners. As Whitehouse concluded, readiness for the vulnerability patch wave will depend on proactive planning, strong fundamentals, and the ability to respond quickly at scale.

Networks of Browser Extensions Are Spyware in Disguise 

Modern browser extensions and ad blockers are legally collecting and reselling user data, including streaming habits and B2B sales intelligence, under the guise of "analytics." This unregulated "legal spyware" creates massive security gaps as employees unwittingly leak corporate URLs, SaaS dashboards, and research activity to third-party databases. With the rise of AI-native browsers and personal device syncing, security leaders must evolve beyond simple permission checks to implement rigorous extension governance and privacy policy reviews to prevent targeted attacks and corporate data leakage.

The post Networks of Browser Extensions Are Spyware in Disguise  appeared first on Security Boulevard.

❌