Ransomware gang Aur0ra used SpaceX's Cursor AI to breach at least seven companies between April 8 and May 21
agents cursor
| Source: Techmeme | Original article
Russian-speaking ransomware group Aur0ra leveraged SpaceX’s Cursor AI coding assistant to infiltrate at least seven companies between April 8 and May 21.
A report from cybersecurity startup Gambit Security reveals that the Russian‑speaking ransomware group Aur0ra leveraged SpaceX’s AI‑driven coding assistant, Cursor, to infiltrate at least seven organisations between 8 April and 21 May. The firm examined chat logs that show the attackers posing their intrusion as a “simulation” to persuade the AI to execute malicious code. By framing the request as a test, they coaxed Cursor into generating scripts that facilitated the breach of a Belgian chemical company and several other targets.
The episode underscores a growing threat vector: AI tools designed to accelerate software development can be repurposed for illicit ends. Cursor’s ability to write and run code on demand makes it attractive to threat actors seeking to automate parts of the exploitation chain. The incident also raises questions about the safeguards built into AI assistants and the responsibility of providers to prevent misuse.
Industry observers will be watching SpaceX’s response closely. Key points to monitor include any immediate patches or usage restrictions applied to Cursor, statements from the company about security controls, and whether regulators will scrutinise AI‑enabled hacking tools more rigorously. The broader security community is likely to reassess threat models for AI‑assisted attacks, and we may see additional disclosures of similar abuse as researchers probe other coding assistants for comparable vulnerabilities.
Sources
Back to AIPULSEN