Tuesday, June 30, 2026
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Artificial Intelligence

New Vulnerability in GitHub Copilot and Cursor: How Hackers Can Weaponize Code Agents Through Compromised Rule Files

March 18, 2025
in Artificial Intelligence, GlobeNewswire, Web3
Reading Time: 5 mins read
5
SHARES
249
VIEWS
Share on TwitterShare on LinkedInShare on Facebook

TEL AVIV, Israel, March 18, 2025 (GLOBE NEWSWIRE) — Pillar Security, a pioneering company in AI security, discovered a significant vulnerability affecting GitHub Copilot and Cursor – the world’s leading AI-powered code editors.

This new attack vector, dubbed the “Rule Files Backdoor,” allows attackers to covertly manipulate these trusted AI platforms into generating malicious code that appears legitimate to developers.

This newly discovered attack vector exploits hidden configuration mechanisms within these tools, enabling attackers to inject malicious code suggestions that blend seamlessly into legitimate AI-generated recommendations and bypass human scrutiny and conventional security checks.

Unlike traditional code injection attacks that target specific vulnerabilities, “Rule Files Backdoor” represents a significant risk by weaponizing the AI itself as an attack vector, effectively turning the developer’s most trusted assistant into an unwitting accomplice.

“This new attack vector demonstrates that rule files can instruct AI assistants to subtly modify generated code in ways that introduce security vulnerabilities while appearing completely legitimate to developers,” said Ziv Karliner, CTO & Co-Founder of Pillar Security. “Developers have no reason to suspect their AI assistant is compromised, as the malicious code blends seamlessly with legitimate suggestions. This represents a fundamental shift in how we must think about supply chain security.”

Key Findings and Implications:

  • Widespread Industry Exposure: The vulnerability affects Cursor and GitHub Copilot, which collectively serve millions of developers and are integrated into countless enterprise development workflows worldwide.
  • Minimal Attack Requirements: Execution requires no special privileges, administrative access, or sophisticated tools–attackers need only manipulate configuration files within targeted repositories.
  • Undetectable Infiltration: Malicious code suggestions blend seamlessly with legitimate AI-generated code, bypassing both manual code reviews and automated security scanning tools.
  • Data Exfiltration Capabilities: Well-crafted malicious rules can direct AI tools to add code that leaks sensitive information while appearing legitimate, including environment variables, database credentials, API keys, and user data–all under the guise of “following best practices.”
  • Long-Term Persistence & Supply Chain Risk: Once a compromised rule file is incorporated into a project repository, it affects all future code generation, with poisoned rules often surviving project forking, creating vectors for supply chain attacks that affect downstream dependencies.

Who is Affected?
A 2024 GitHub survey found that nearly all enterprise developers (97%) are using Generative AI coding tools. According to Pillar, because these rule files are shared and reused across multiple projects, one compromised file can lead to widespread vulnerabilities. The research identified several propagation vectors:

  1. Developer Forums and Communities: Malicious actors sharing “helpful” rule files that unwitting developers incorporate
  2. Open-Source Contributions: Pull requests to popular repositories that include poisoned rule files
  3. Project Templates: Starter kits containing poisoned rules that spread to new projects
  4. Corporate Knowledge Bases: Internal rule repositories that, once compromised, affect all company projects

Mitigation

To mitigate this risk, we recommend the following technical countermeasures:

  1. Audit Existing Rules: Review all rule files in your repositories for potential malicious instructions, focusing on invisible Unicode characters and unusual formatting
  2. Implement Validation Processes: Establish review procedures specifically for AI configuration files, treating them with the same scrutiny as executable code
  3. Deploy Detection Tools: Implement tools that can identify suspicious patterns in rule files and monitor AI-generated code for indicators of compromise
  4. Review AI-Generated Code: Pay special attention to unexpected additions like external resource references, unusual imports, or complex expressions

Following responsible disclosure practices, Pillar alerted both Cursor (February 26) and GitHub (March 12), who responded that users bear responsibility for reviewing AI-generated code suggestions.

“Given the growing reliance on AI coding assistants within development workflows, we believe it’s essential to raise public awareness about potential security implications. We have reached an era where AI coding assistants must be regarded as critical infrastructure,” said Karliner.

Link to the full report: www.pillar.security/blog/new-vulnerability-in-github-copilot-and-cursor-how-hackers-can-weaponize-code-agents

About Pillar Security

Pillar is a unified, end-to-end AI security platform that accelerates AI initiatives by establishing robust security foundations across the entire AI lifecycle. By embedding security from development through runtime, Pillar enables organizations to ship AI-powered applications and agents with confidence while managing critical business risks.

The platform’s comprehensive capabilities—including AI fingerprinting, asset inventory, and deep integration with development and data platforms—create a secure foundation that prevents data breaches and ensures compliance. Through tailored adversarial AI testing and adaptive guardrails aligned with industry standards, Pillar removes security bottlenecks, allowing teams to innovate and deploy AI faster without compromising on security.

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.
ShareTweet1ShareSendShare2
Previous Post

Notice to annual general meeting in Agillic A/S

Next Post

Nerdio Secures $500 Million in Series C Investment from General Atlantic at $1 Billion+ Valuation

Related Posts

Vadzo Imaging Positions Falcon-821CRS as Precise Dermatology Camera Module with 4K HDR for Skin Tone Accuracy

The Falco -821CRS is a 8MP 4K HDR de matology came a module built o the O semi AR0821 Hype Lux se so . Positio ed fo de moscopy, ski lesio assessme t, telede matology platfo ms, a d cli ical de matology wo kflows, this colo -accu ate USB...

Read moreDetails

Arovy and Spotlight Monitor Announce Strategic Partnership to Accelerate Salesforce Shield Event Monitoring Adoption and Stop Breaches

Pa t e ship e ables o ga izatio s to deploy Shield Eve t Mo ito i g i mi utes, detect th eats i eal time, a d tu aw eve t data i to actio able secu ity outcomes. ATLANTA, GA / ACCESS Newswi e / Ju...

Read moreDetails

Babbily Launches Finance and Updates News to Bring Real-Time Market Context, Source-Backed Stories, and AI-Powered Discovery Into One Workspace

Babbily Fi a ce adds ma ket summa ies, compa y pages, p edictio ma kets, a d fi a cial ews-style a ticles, while the ef eshed News expe ie ce delive s clea e discove y, local co text, a d iche sou ce-backed epo ti g. DENVER,...

Read moreDetails

Vadzo Imaging Launches AR0521 USB Camera for Interactive Digital Signage and Real-Time Gesture Recognition Applications

Vadzo Imagi g's Falco -521CRS is a 5MP USB 3.0 colo came a built o the O semi AR0521 se so , delive i g low oise olli g shutte imagi g with full UVC complia ce fo i te active kiosk systems, digital sig age displays, a d eal-time...

Read moreDetails

SKADI Cyber Defense Partners with Sharp Electronics of Canada to Expand Access to Canadian-Built Autonomous Cybersecurity

BRACEBRIDGE, ON / ACCESS Newswi e / Ju e 29, 2026 / SKADI Cybe Defe se Co po atio today a ou ced a st ategic pa t e ship with Sha p Elect o ics of Ca ada Ltd., b i gi g F ostbow™, SKADI's auto omous cybe...

Read moreDetails

Avahi Earns Two 2026 Bronze Stevie Awards for AI-Driven Results in Healthcare and Financial Services

Sa F a cisco, CA, Ju e 29, 2026 (GLOBE NEWSWIRE) -- Avahi I c., a Amazo Web Se vices (AWS) P emie Tie Se vices Pa t e , has bee amed a two-time B o ze Stevie® Awa d wi e at the 2026 Ame ica Busi ess...

Read moreDetails

Profound Launches the Profound Index at Zero Click New York, Creating the Definitive Benchmark for AI Search Visibility

NEW YORK, Ju e 29, 2026 (GLOBE NEWSWIRE) --  P ofou d, the ma keti g platfo m fo the AI e a, today a ou ced the lau ch of the P ofou d I dex at Ze o Click New Yo k, the compa y's seco d a...

Read moreDetails

Gimlet Labs Joins MLCommons as a Member Company to Establish Vendor-Agnostic Benchmarks for Agentic Inference and Accelerate Innovation

SAN FRANCISCO, Ju e 29, 2026 (GLOBE NEWSWIRE) -- Gimlet Labs, the Applied AI esea ch a d p oduct compa y, today a ou ced that it has joi ed MLCommo s®. This AI i dust y e gi ee i g co so tium delive s ope ,...

Read moreDetails

Patton and XOP Networks Partner to Deliver Secure IP/SIP Emergency Communications

Joi t solutio combi es XOP platfo ms with Patto 's To e Comma de secu e SIP e dpoi t platfo m fo missio -c itical comma d-a d-co t olPatto ®... Let's Co ect! “Togethe with Patto , we a e delive i g a flexible solutio that...

Read moreDetails

Cority’s Environmental, Health and Safety Solutions Now Available on Carahsoft’s GSA Schedule Contract

TORONTO a d RESTON, Va., Ju e 29, 2026 (GLOBE NEWSWIRE) -- Co ity, the co ve ged platfo m fo p eve ti g EHS+ isks i ope atio s, a d Ca ahsoft Tech ology Co p., The T usted Gove me t IT Solutio s P ovide ®,...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • Top Cross-Chain DeFi Solutions to Watch by 2025

    151 shares
    Share 60 Tweet 38
  • GENISOM AI Debuts at ICRA 2026 with Full-Stack Embodied Intelligence System

    44 shares
    Share 18 Tweet 11
  • Top Layer 1 Crypto Projects to Watch in 2025

    21 shares
    Share 8 Tweet 5
  • Understanding Soulbound Tokens SBT Their Definition and Significance

    69 shares
    Share 28 Tweet 17
  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    173 shares
    Share 69 Tweet 43
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

There are currently no events.

Latest on Web3Wire

  • Vadzo Imaging Positions Falcon-821CRS as Precise Dermatology Camera Module with 4K HDR for Skin Tone Accuracy
  • Arovy and Spotlight Monitor Announce Strategic Partnership to Accelerate Salesforce Shield Event Monitoring Adoption and Stop Breaches
  • Babbily Launches Finance and Updates News to Bring Real-Time Market Context, Source-Backed Stories, and AI-Powered Discovery Into One Workspace
  • Vadzo Imaging Launches AR0521 USB Camera for Interactive Digital Signage and Real-Time Gesture Recognition Applications
  • SKADI Cyber Defense Partners with Sharp Electronics of Canada to Expand Access to Canadian-Built Autonomous Cybersecurity

RSS Latest on Block3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age

RSS Latest on Meta3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Founder’s Note
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Web3Wire Whitepaper | Tokenomics

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!

The Klyrox Protocol | The Algorithmic Monographs

Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News

Media Portfolio: Block3Wire | Meta3Wire

  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.