HomeSample Page

Sample Page Title


Ravie LakshmananMar 19, 2026Cybersecurity / Hacking Information

FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & Extra

ThreatsDay Bulletin is again on The Hacker Information, and this week feels off in a well-known approach. Nothing loud, nothing breaking all the pieces without delay. Simply plenty of small issues that shouldn’t work anymore however nonetheless do.

A few of it appears easy, virtually sloppy, till you see how effectively it lands. Different bits really feel slightly too sensible, like they’re already nearer to real-world use than anybody desires to confess. And the background noise is getting louder once more, the type folks normally ignore.

A couple of tales are intelligent in a foul approach. Others are simply frustratingly avoidable. General, it appears like quiet stress is constructing in locations that matter.

Skim it or learn it correctly, however don’t skip this one.

  1. Deep hyperlink abuse allows command execution

    Proofpoint has detailed a brand new approach referred to as CursorJack that abuses Cursor’s help for Mannequin Context Protocol (MCP) deep hyperlinks to allow native command execution or permit set up of a malicious distant MCP server. The assault takes benefit of the truth that MCP servers generally specify a command of their “mcp.json” configuration. “The cursor:// protocol handler might be abused by social engineering in particular configurations,” the corporate mentioned. “A single click on adopted by consumer acceptance of an set up immediate might lead to arbitrary command execution. The approach might be leveraged each for native code execution through the command parameter or to put in a malicious distant MCP server through the URL parameter.” The enterprise safety agency has additionally launched a proof-of-concept (PoC) exploit on GitHub.

A few of it will fade by subsequent week. A few of it gained’t. That’s the annoying half, determining which “minor” factor quietly sticks round and turns into an actual downside later.

Anyway, that’s the rundown. Take what you want, ignore what you possibly can, and keep watch over the stuff that feels slightly too simple.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles