NewsIDEsaster 30+ Vulnerabilities Across Every Major AI IDE 100% VulnerableSC Media·high signalXBlueskyLinkedInCopy linkAri Marzouk disclosed 30+ vulns (24 CVEs) affecting Cursor, Copilot, Windsurf, Zed, Kiro, Roo Code, Junie, Cline. 100% of tested IDEs vulnerable to prompt injection enabling RCE.SourceSource pageSC Media↳ Follow the threadPolicy dependency / Stack layerAttnlocate treats prompt injection as an object detection problem inside the attention matrix, hitting 0.934 TPR at 0.067 FPRarXivStack layer / Threat patternCyberFactory Turns CVEs From the Wild Into Executable Training Tasks; Aegis Hits 52.4% Pass@1 on CyberGym, +22.8 Over Its BasearXiv 2608.23181Stack layer / Threat patternTwo New Self-Hostable Git Forges Hit the HN Front Page a Week After Cursor Shipped OriginCodefloe and github.com/tobi/walgit (via Hacker News, 2026-08-24)Stack layer / Threat patternCline v4.1.16 fixes hooks resolving from global state, and starts redacting credentials embedded in git remote URLs before they reach the modelGitHub (cline/cline)Policy dependency / Stack layerWebMCP-Phalanx blocks all 80 tool-description injections in a browser agent, then gets bypassed by a malicious tool name called before inspectionarXivStack layer / Threat patternAnthropic's own weekly sales digest runs on Claude Code plus a BigQuery MCP connector and nine hand-written content rulesClaude by AnthropicPolicy dependency / Stack layerA flow-centric policy language cut confirmed agent compromise from 33% to 0% on AgentDojo while raising utilityarXiv 2608.22868Stack layer / Threat patternMicrosoft's Agent Lightning v1.0.1 ships an agent skill whose job is optimizing other agents, installed through gh skillGitHub