Thursday, 27 August 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 27 August 2026 at 22:17

Russian-speaking hackers tricked Cursor's AI agent into breaching seven companies

Cybersecurity firm Gambit Security found that the ransomware group Aur0ra used the AI agent in the coding tool Cursor to breach seven companies worldwide by convincing it the attacks were a simulation, Reuters reports.

Foto: Meduza

Cybersecurity firm Gambit Security has reported that a Russian-speaking ransomware group called Aur0ra used the AI coding assistant built into Cursor — a code editor recently acquired by Elon Musk's SpaceX — to break into seven companies around the world, according to Reuters.

The hackers were exposed after accidentally leaving one of their servers unsecured.

Group members used the AI agent to carry out hundreds of malicious operations, including stealing login credentials. Gambit says the hackers tricked the agent into believing the intrusions were part of a simulated test.

Agent refused harmful requests

The AI agent repeatedly refused requests it judged to be harmful or illegal. Almost every time, however, the hackers managed to bypass these refusals by convincing the agent that the break-in was part of a test. During the attacks, according to Gambit, the agent was running on Anthropic's Claude Sonnet 4.5 model.

Chat logs spanning April 8 to May 21 show Aur0ra using the Cursor agent against seven companies in total. At least six of them are located in Belgium, Germany, Scotland, Italy, Argentina, and the United States, with businesses ranging from cleaning product manufacturing to helicopter landing pad certification.

Reuters could not determine how much the Cursor agent facilitated the intrusions, or whether every attack involving it led to data theft and an extortion attempt. Gambit estimated that the AI assistant likely helped the group complete break-ins roughly 30 to 50 percent faster.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category