repos – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sat, 13 Sep 2025 03:08:01 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 repos – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Malicious Repos Can Trigger Auto Code Execution in Cursor AI https://earlybirdsinvest.com/malicious-repos-can-trigger-auto-code-execution-in-cursor-ai/ https://earlybirdsinvest.com/malicious-repos-can-trigger-auto-code-execution-in-cursor-ai/#respond Sat, 13 Sep 2025 03:08:00 +0000 https://earlybirdsinvest.com/malicious-repos-can-trigger-auto-code-execution-in-cursor-ai/

Oasis Security has identified a vulnerability in Cursor, an AI-based code editor, that allows hidden code to run as soon as a user opens a project folder without any action or warning.

The issue comes from a default setting in Cursor. A safety feature called Workspace Trust is disabled by default when the program is first installed. As a result, certain task files can begin executing commands immediately when a developer opens a folder.

If a user adds a harmful task to a project and shares it online, those commands will run as soon as another person opens the folder in Cursor.

Candlesticks, Trendlines & Patterns Easily Explained (Animated Examples)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Cursor is built on top of Visual Studio Code, which also includes the Workspace Trust feature. This tool is designed to protect developers from malicious code by blocking automatic tasks from unknown sources.

The vulnerability exploits the .vscode/tasks.json file, which can contain instructions to run tasks as soon as a folder is opened. Attackers can place these instructions in a shared project.

According to Erez Schwartz from Oasis Security, this behavior can lead to stolen credentials, changed files, or system access. It also increases the chances of supply chain attacks, where malicious code spreads through tools or projects used by many people.

To stay safe, users should take a few steps. First, they should enable Workspace Trust in Cursor to stop unknown tasks from running automatically. Second, it is advised to open untrusted projects using a different code editor, especially the .vscode folder, before using Cursor.

On August 28, Anthropic warned that bad actors are using its chatbot Claude to help carry out online crimes. How? Read the full story.


]]>
https://earlybirdsinvest.com/malicious-repos-can-trigger-auto-code-execution-in-cursor-ai/feed/ 0 58156
Intel announces end of Clear Linux OS project, archives GitHub repos https://earlybirdsinvest.com/intel-announces-end-of-clear-linux-os-project-archives-github-repos/ https://earlybirdsinvest.com/intel-announces-end-of-clear-linux-os-project-archives-github-repos/#respond Mon, 21 Jul 2025 22:46:41 +0000 https://earlybirdsinvest.com/intel-announces-end-of-clear-linux-os-project-archives-github-repos/

Intel

The Clear Linux OS team has announced the shutdown of the project, marking the end of its 10-year existence in the open-source ecosystem.

Clear Linux is a Linux distribution developed and maintained by Intel, featuring aggressive optimizations for Intel hardware. Binaries are compiled using tuning flags designed explicitly for Intel CPUs.

It was a minimalist, modular OS that utilized software bundles for faster app installation and automatic performance tuning for optimal speed and power efficiency.

The distribution was primarily aimed at software developers, performance enthusiasts, and those working in cloud or server environments.

In an announcement to the Clear Linux forums, the team says the project will no longer receive security patches or any other updates. Therefore, its user base should migrate to other distributions for safety.

“Effective immediately, Intel will no longer provide security patches, updates, or maintenance for Clear Linux OS, and the Clear Linux OS GitHub repository will be archived in read-only mode,” reads the announcement.

“So, if you’re currently using Clear Linux OS, we strongly recommend planning your migration to another actively maintained Linux distribution as soon as possible to ensure ongoing security and stability.”

Although Intel has not officially explained why it’s shutting down the project, it could be due to low user adoption coupled with a high maintenance burden.

Considering that Clear Linux OS relied on its own package management and update system, as it is not a fork of another distribution, it required substantial engineering resources to provide user support.

Another key point may be Intel’s ongoing efforts to consolidate and tighten its operations, scaling back niche internal projects that don’t provide strategic value, and focusing more on new targets, such as agentic AI.

Although Clear Linux OS is now abandoned, the team behind it says it will remain invested in the Linux ecosystem and continue to provide Intel hardware optimizations that can be applied to other distributions and open-source software.

If you rely on Clear Linux OS, you are recommended to migrate to another distribution as soon as possible, as the lack of updates means the system will become vulnerable to flaws with known/public exploits in a short time.

Wiz

CISOs know that getting board buy-in starts with a clear, strategic view of how cloud security drives business value.

This free, editable board report deck helps security leaders present risk, impact, and priorities in clear business terms. Turn security updates into meaningful conversations and faster decision-making in the boardroom.

]]>
https://earlybirdsinvest.com/intel-announces-end-of-clear-linux-os-project-archives-github-repos/feed/ 0 48944