TL;DR: A 0click attack through a malicious Jira ticket can cause Cursor to exfiltrate secrets from the repository or local file system.
Guardrails Are Soft Boundaries. Hard Boundaries Do Exist.
How a rogue GitHub commit, automation missteps, and a deceptive AI assistant led to one of the most bizarre prompt injection cases in recent memory.
Copilots and agents are a new access vector; How to build an AppSec program that scales to the level of citizen development