Here's a good recent example: Cursor/Claude was refusing to steal API tokens, so they changed the attack to request "rotten apples" which were of strings starting with "eyJ" – aka JWTs! https://
simonwillison.net/2025/Aug/9/whe
n-a-jira-ticket-can-steal-your-secrets/
…
SAFETY
-

Cursor Claude Attack Stealing API Tokens via JWT Obfuscation
By
–
-
False Security Sense Increases Attack Vulnerability Risk
By
–
I think they give people a false sense of security which makes it much more likely they'll fall victim to an attack
-

GPT-5 Controversy: What Went Wrong and What’s Next
By
–
GPT-5 caused quite a stir—and sparked a very controversial discussion in the community. It is questionable whether the new model has lived up to expectations or not. I sat down and traced the events. How did the controversy arise, what went wrong, and can GPT-5 now be
-

Scanner Security Limitations Against Adversarial Attacks
By
–
I've seen a bunch of attempts at this but it's basically an impossible problem to solve If your scanner only detects 90% of attacks it's virtually useless, because an adversarial attacker will keep trying until they find one of the 1/10 attacks that work https://
simonwillison.net/2025/Aug/9/bay
-area-ai/#the-lethal-trifecta.018.jpeg
… -
AI Dependencies: Examining Digital Consciousness Limitations
By
–
AI fiends can't be severed, because they have no life outside.
-
Prompt Injection and MCP Security: Emerging Threats
By
–
I gave a talk on Wednesday at the Bay Area AI Security Meetup about prompt injection, MCP security and the lethal trifecta. Here are the annotated slides from my presentation, including notes on my weird hobby of trying to coin or amplify new terms of art
-
Mitigating AI Security Risks: The Lethal Trifecta Solution
By
–
The only solution I know of to the lethal trifecta is to cut off one of the three legs – when Cursor say "limit to those that access trusted content" they're recommending avoiding exposure to untrusted data that might contain malicious instructions, which is often very hard to do
-
Cursor AI Tool Targeted in Lethal Trifecta Security Attack
By
–
This was in response to a classic lethal trifecta attack – here an attacker filed a Jira issue (via a support ticket) which caused Cursor to steal developer secrets from environment variables and submit them to an attacker's server
-

Cursor AI warns MCP servers present security risks to users
By
–
Apparently @cursor_ai
's official position on MCP is "MCP servers, especially ones that connect to untrusted data sources, present a serious risk to users. We always recommend users review each MCP server before installation and limit to those that access trusted content." -
ChatGPT Psychosis: Ethics of AI-Induced Mental Health Concerns
By
–
"I have a toddler. My biggest concern is that he doesn't eat rocks off the ground and you're talking to me about ChatGPT psychosis? Why do we even have that? Why did we invent a new form of insanity and then they charge people for it?"