By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: CursorJack, deeplink attack for AI development
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Mobile > CursorJack, deeplink attack for AI development
Mobile

CursorJack, deeplink attack for AI development

News Room
Last updated: 2026/04/11 at 5:47 AM
News Room Published 11 April 2026
Share
CursorJack, deeplink attack for AI development
SHARE

Press release. CursorJack, a method to potentially abuse Cursor MCP deeplinks, could allow code execution or installation of a malicious remote MCP serveraccording to research by the cybersecurity company Proofpoint.

An MCP server is a standardized program that links AI with tools, APIs, databases and local files, to access data and perform actions securely, without having to integrate each tool individually. Deeplinks, meanwhile, are custom URL schemes to direct users to specific pages within an application. The Cursor IDE implements MCP deeplinks for quick installation of MCP servers, which are capable of creating a new attack vector in AI development tools.

The proliferation of AI coding assistants has normalized approval requests, and Cursor executes commands with user privileges when users accept the installation request. IDEs that support MCP servers are typically deployed on developer workstations that may have privileged access, including API tokens, cloud credentials, source code, and access to production systems.

“As users are encouraged to adopt AI, many are writing and running code for the first time without fully understanding the security implications, which makes developers a target for cybercriminals”point out the Proofpoint researchers.

Deeplinks can use any name, which can be used to impersonate legitimate MCP servers, such as Azure DevOps, through social engineering, without verification that the deeplink originates from the declared provider. It is up to the users to review the parameters before approving. EDR controls, permission lists, and operating system policies can limit or block abuse depending on configuration.

The malicious behaviors analyzed by Proofpoint correspond to test environments and do not imply silent or zero-click exploitation by default. In their research, a single click followed by the user’s acceptance of an installation request executed arbitrary commands, which “underscores the urgent need to secure agentic AI environments”declare the experts.

For Proofpoint, the MCP ecosystem requires security enhancements embedded directly into its architecture, rather than relying on additional security tools or user surveillance as a primary defense. Deeplinks from untrusted sources should be treated with the same caution as untrusted executables. Approval flows should incorporate granular security warnings and origin verification to help users distinguish deeplinks from trusted and untrusted locations.

A trusted ecosystem with verified signatures and publishers for MCP servers, analogous to those for browser extensions or app installers, would establish the authenticity of the server. Additionally, a robust code signing mechanism would ensure that users can verify the source and integrity of servers before installation, creating a marketplace-like environment for trusted MCP integrations.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article I’ve been a Kindle user for 10+ years — and I may never buy another one I’ve been a Kindle user for 10+ years — and I may never buy another one
Next Article OpenAI Launches 0 ChatGPT Pro Plan with 5x Codex Limits — Everything You Need to Know – Chat GPT AI Hub OpenAI Launches $100 ChatGPT Pro Plan with 5x Codex Limits — Everything You Need to Know – Chat GPT AI Hub
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Microsoft denies shutting down operations in China · TechNode
Microsoft denies shutting down operations in China · TechNode
Computing
How Apple’s iPhone Is Responsible For Futurama’s Most Memed Moment – BGR
How Apple’s iPhone Is Responsible For Futurama’s Most Memed Moment – BGR
News
BEYOND Expo 2025: BEYOND × wteam Launch the ‘Gen Z Innovation’ List · TechNode
BEYOND Expo 2025: BEYOND × wteam Launch the ‘Gen Z Innovation’ List · TechNode
Computing
I tried the redesigned Google Wallet app, and it fixes my 2 biggest complaints
I tried the redesigned Google Wallet app, and it fixes my 2 biggest complaints
News

You Might also Like

vertical tabs and split screen
Mobile

vertical tabs and split screen

6 Min Read
the 5 decisions that almost killed the company before it dominated the world
Mobile

the 5 decisions that almost killed the company before it dominated the world

11 Min Read
making history. Orion has landed after a mission that we have not seen since Apollo
Mobile

making history. Orion has landed after a mission that we have not seen since Apollo

6 Min Read
how to avoid the increase that arrives in May?
Mobile

how to avoid the increase that arrives in May?

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?