The Solidity Language open-source package was used in a $500,000 crypto heist
Code highlighting with Cursor AI for $500,000
Kaspersky GReAT experts uncover malicious extensions for Cursor AI that download the Quasar backdoor and a crypto stealer.Georgy Kucherin (Kaspersky)
HumanPerson
in reply to Pro • • •Someone used a hammer to smash a window and steal stuff. Quick, ban hammers!!!
Getting rid of the tools to exploit vulnerabilities doesn't get rid of the vulnerabilities, and security by obscurity is not security.
Jonathan Lamothe
in reply to HumanPerson • •youtu.be/H2S7PKWaP7c
cybersecurity reshared this.
kristoff
in reply to HumanPerson • • •kristoff
in reply to HumanPerson • • •Concerning this particular article, perhaps the vulnerability here are not a mallicious software packages, but the management of these software repo's.
Should it be possible to upload a package on a repo with 99% of the same name as one that already exists without some additional checks?