>_ Posts

Blog

Thoughts on development, engineering, and product.

1 post
  • 01|

    Opening a folder in Cursor can run malicious code by itself — and Cursor has known for seven months

    An unpatched zero-day in Cursor for Windows lets any repository with a forged git.exe in its root execute code automatically, with no click, no warning, no confirmation. Mindgard reported it in December 2025; it went fully public in July 2026, after seven months of silence.