Hackers used an AI coding tool to breach seven companies

A Russian-speaking ransomware group used Cursor, a commercial AI coding tool, to help breach at least seven companies this spring, according to a report from the security research firm Gambit Security that Reuters reviewed and independently corroborated in part.
Gambit said it found the campaign after discovering a server that the group, which calls itself Aur0ra, had accidentally left exposed to the open internet. The server held 28 chat sessions between the hackers and Cursor's AI agent, spanning April 8 to May 21, which Gambit says show the tool being used to help plan intrusions and escalate access inside compromised networks.
Reuters said it independently verified six of the victims: Christeyns, a Belgian maker of hygiene and cleaning products; Teckentrup, a German garage door manufacturer; the Helideck Certification Agency, a Scotland-based firm that certifies helicopter landing sites; an Argentine pharmaceutical distributor; an Italian manufacturer; and Bayou Title, which describes itself as Louisiana's largest title insurance company. Bayou Title later turned up on Aur0ra's own data-leak site, which typically means the group tried to extort a ransom and failed to collect.
Gambit's Eyal Sela said the AI tool likely made the hackers meaningfully faster rather than more capable: it "probably helps them get 30, 40, 50 percent faster because it helps them skip over all the things they'd have to do manually." His colleague Curtis Simpson called the pattern the start of a prolonged standoff: "This is going to be a cat-and-mouse game," as AI providers tighten safeguards and attackers keep finding ways around them.
Cursor is made by Anysphere, the startup behind the coding assistant; SpaceX agreed in June to acquire Anysphere in an all-stock deal reported at a $60 billion valuation, though the deal was still pending regulatory approval and had not closed when the attacks described here took place. The episode is the latest in a run of incidents this year in which commercial AI coding tools built for legitimate work have been repurposed for intrusions, underscoring that AI labs cannot fully separate a tool's productivity gains from what it hands to whoever is using it, criminal or not.
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Trending now
- US-China Trade Truce Extended to Jan. 10 as Xi Visits
- Amoeba Breeds at 63°C, Past the 60°C Limit for Complex Life
- 996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
- Oracle Invokes Force Majeure on 2.45GW Stargate Data Center
- Diller Drops $18B MGM Bid; Stock Falls 9.5% to February Levels
- Taylor Swift Adds 4 Songs to ‘Showgirl’ in Sept. 25 Encore
- Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
- Rivian Recalls 98,828 EVs Over Rearview Camera Fault
Comments
No comments yet. Be the first.