CursorJack: deep links abused to trigger unwanted actions in Cursor
Proofpoint has described an attack technique called CursorJack that abuses deep links and custom URI handlers in the Cursor IDE. By weaponising specially crafted links, an attacker can trigger unintended behaviour in the application when a user clicks or interacts with them, including arbitrary command execution or injection of malicious workflows.
What this means for your organisation
Development tools have access to source code, secrets and build processes, so an action triggered inside the tool can reach far beyond a single machine. AI-assisted development tools are adopted quickly and often without the review applied to other business software. That gap between rapid adoption and governance is what makes this technique a leadership concern, not only a developer one.
Berigo recommends
- Establish visibility into which AI-assisted development tools are actually in use and what access they hold.
- Keep the tools updated and follow vendor security advisories as you would for other critical software.
- Ensure developers do not work with production secrets locally, and that keys can be revoked quickly.
- Bring AI tooling into the governance model, with an assessment requirement before adoption.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch