Cursor flaw lets extensions steal API keys and session tokens without user interaction, according to researchers at LayerX ...
Cursor, running on Claude Code's AI model, deleted an entire database from cloud storage.