Dark Reading (Jul 2026): Industry coverage + vendor posture.
- Mindgard research: malicious git.exe in repo root → silent RCE on open
- Portnoy (ex-ZDI): simple to fix, easy to operationalize
- Cursor told Dark Reading it was working on a fix and would follow up
- Portnoy: frames as CWE-426/427 untrusted search path, not customer misuse
- Notes Cursor fixed a different Git-related report in v2.5 while this sat