“Unfortunately, due to the natural language nature of rapid injection, blocking using a classifier or any kind of blacklist is not sufficient,” they said in the report. “There are too many ways to write them, hiding behind benign topics and using different phrases, tones, languages, etc. It's the same with quick injections, just as you think that the malware isn't fixed because another sample has become a rejection list.”
Hijack cursor coding assistant via Jira ticket
As part of the same research effort, Zenity also looked into Cursor, one of the most popular AI assist code editors and IDEs. Cursor can integrate with many third-party tools, including Jira, one of the most popular project management platforms used for problem tracking.
“You can look up assigned tickets, summarise open issues, or ask them to close tickets from within the editor or respond automatically,” the researcher said. “But tickets aren't always created by developers. In many companies, tickets from external systems like Zendesk are automatically synced to JIRA. This means that external actors can send emails to support addresses connected to Zendesk and inject unreliable input into the agent's workflow.”
