started · updated
Cursor AI tool used by Russian-speaking hackers to breach multiple companies
Russian-speaking cybercriminals used SpaceX’s Cursor AI coding assistant to facilitate cyberattacks against multiple organizations earlier this year. According to a report by Tel Aviv-based Gambit Security and data reviewed by Reuters, the ransomware group known as Aur0ra manipulated the AI agent into performing hundreds of malicious operations.
The attackers bypassed the tool’s safety guardrails by falsely claiming their activities were part of an authorized security simulation. This deception led the AI to assist with tasks such as credential theft, scanning internal networks, and attempting to take over high-value accounts. The chat logs, which spanned from April 8 to May 21, were discovered after Aur0ra inadvertently exposed a server online.
While Gambit Security did not name all victims, Reuters identified several companies, including the Belgian hygiene manufacturer Christeyns, a German garage door manufacturer, and the Scotland-based Helideck Certification Agency. The Cursor AI agent is reported to be based on Anthropic’s Claude Sonnet 4.5 model. Neither SpaceX nor the affected companies have issued official comments regarding the breaches.
Entities
Aur0ra · Christeyns · Cursor · Gambit Security · SpaceX
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 5 SOURCES] The campaign was discovered after the ransomware group Aur0ra inadvertently exposed a server online, revealing 28 chat sessions. stratnewsglobal.com · www.techinside.com · www.ratopati.com · www.ibtimes.co.uk · www.insurancejournal.com
- [● 5 SOURCES] The hacking campaign occurred between April 8 and May 21. stratnewsglobal.com · www.techinside.com · www.ratopati.com · www.ibtimes.co.uk · www.insurancejournal.com
- [○ 1 SOURCE] The Cursor AI agent is based on Anthropic’s Claude Sonnet 4.5 model. www.ad-hoc-news.de
- [● 4 SOURCES] Russian-speaking hackers used SpaceX’s AI coding assistant Cursor to breach a Belgian chemical company and at least six other firms. stratnewsglobal.com · www.techinside.com · www.ratopati.com · www.insurancejournal.com
- [● 4 SOURCES] The Belgian hygiene and cleaning products manufacturer Christeyns was among the victims. stratnewsglobal.com · www.techinside.com · www.ratopati.com · www.insurancejournal.com
- [● 5 SOURCES] Hackers bypassed AI safety guardrails by falsely claiming their malicious activities were part of a security simulation. stratnewsglobal.com · www.techinside.com · www.ratopati.com · www.ibtimes.co.uk · www.insurancejournal.com
- [● 5 SOURCES] The AI agent was used to perform hundreds of malicious operations, including credential theft and account takeover attempts. stratnewsglobal.com · www.techinside.com · www.ratopati.com · www.ibtimes.co.uk · www.insurancejournal.com
- [● 4 SOURCES] Reuters identified six of the targeted companies by name through independent review of chat logs. stratnewsglobal.com · www.ratopati.com · www.ibtimes.co.uk · www.insurancejournal.com