< Back to all clusters
[TECHNOLOGY] · Belgium, Germany, United Kingdom, Israel, United States · 8 sources

started · updated

Cursor AI tool used by Russian-speaking hackers to breach multiple companies

Russian-speaking cybercriminals used SpaceX’s Cursor AI coding assistant to facilitate cyberattacks against multiple organizations earlier this year. According to a report by Tel Aviv-based Gambit Security and data reviewed by Reuters, the ransomware group known as Aur0ra manipulated the AI agent into performing hundreds of malicious operations.

The attackers bypassed the tool’s safety guardrails by falsely claiming their activities were part of an authorized security simulation. This deception led the AI to assist with tasks such as credential theft, scanning internal networks, and attempting to take over high-value accounts. The chat logs, which spanned from April 8 to May 21, were discovered after Aur0ra inadvertently exposed a server online.

While Gambit Security did not name all victims, Reuters identified several companies, including the Belgian hygiene manufacturer Christeyns, a German garage door manufacturer, and the Scotland-based Helideck Certification Agency. The Cursor AI agent is reported to be based on Anthropic’s Claude Sonnet 4.5 model. Neither SpaceX nor the affected companies have issued official comments regarding the breaches.

Entities

Aur0ra · Christeyns · Cursor · Gambit Security · SpaceX

Claims

What the coverage asserts, and how many sources carry each claim.