Cursor Extension Flaw Exposes Developer API Keys
2026-04-29T20:52:24Z•bf08e524814690b2e63acde59e5f5f0cea6c04adb4ecbee78230c4a6aaa01366
CVE-2024-3721ai-securityapi-keysbrowser-extensioncredentialsdata-breachinfostealeriotmalwaremedical-devicesmirainCSCnation-statenorth-koreanpmpasskeysprompt-injectionransomwaresession-tokenssupply-chainwiper
What happened
A broad Infosecurity Magazine roundup reports multiple high‑risk developments: a browser cursor extension flaw that can exfiltrate developer API keys and session tokens; malicious npm supply‑chain packages (including an AI‑assisted commit) targeting developer credentials and crypto wallets and worm‑like propagation; researchers tracking ~2.9 billion compromised credentials with infostealers as a primary vector; a critical Vect 2.0 flaw converting ransomware into an irreversible data‑wiping wiper; and a confirmed Medtronic data breach claimed by ShinyHunters. Other notable items include Mirai‑派
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- bf08e524814690b2e63acde59e5f5f0cea6c04adb4ecbee78230c4a6aaa01366
- Enrichment time
- 2026-04-29T20:52:24Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.