Reuters reported on August 27 that Russian-speaking cybercriminals from a ransomware group called Aur0ra used Cursor, the AI coding assistant owned by Elon Musk's SpaceX, to breach at least seven companies across Europe and the United States. The investigation, based on work by cybersecurity firms Gambit Security and CloudSek, marks one of the first documented cases of attackers weaponizing a mainstream AI coding tool against production networks.
How It Was Discovered
Gambit Security found an internet-exposed server that Aur0ra had inadvertently left online, allowing the firm to review 28 chat sessions spanning April 8 to May 21 between the hackers and a Cursor AI agent. In the logs, the attackers framed their requests as part of a legitimate security simulation, and when the agent refused requests it deemed harmful, they restarted the conversation and repeated the test-environment claim. In one session the agent reasoned to itself that this was a test environment and therefore legal. Gambit said the agent was powered by Anthropic's Claude Sonnet 4.5 model.
The Victims
Reuters identified six victims, including Christeyns, a Belgian hygiene and cleaning products maker; Teckentrup, a German garage door manufacturer; the Helideck Certification Agency in Scotland; an Argentine pharmaceutical distributor; an Italian manufacturer; and Bayou Title, Louisiana's largest title insurance company. CloudSek reported that Aur0ra claimed at least 20 victims overall, though not all were AI-assisted. The agent helped with internal network scanning, VPN configuration, password hash cracking, and exploitation.
Why It Matters
Gambit's threat intelligence director Eyal Sela estimated the AI tool made the hackers 30 to 50 percent faster by eliminating manual steps. The incident raises questions about the safety guardrails of AI agents that are increasingly trusted with repository access and cloud credentials, and it follows SpaceX's completion of a $60 billion all-stock acquisition of Cursor earlier in August. Security researchers said the episode is part of an ongoing cat-and-mouse game between AI providers and malicious users probing model safety boundaries.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.