Hacker group used artificial intelligence service SpaceX Cursor to invade the resources of 7 companies

Hacker group used artificial intelligence service SpaceX Cursor to invade the resources of 7 companies

According to reports, the hacker group Aur0ra used the SpaceX Cursor artificial intelligence program assistant service to invade the resources of 7 companies from different countries. Reuters Refer to reports from cybersecurity experts Gambit Security and CloudSek.

    Image credit: Kevin Ku/unsplash.com

Image credit: Kevin Ku/unsplash.com

The incident shows that artificial intelligence developers are locked in an endless race with attackers trying to bypass its protections. Gambit discovered this malicious activity by discovering servers that the Aur0ra ransomware group inadvertently exposed online. This allowed experts to analyze 28 conversations between one or more hackers and Cursor AI agents. The attackers convinced an artificial intelligence agent to perform hundreds of malicious actions, including credential theft and account takeover, claiming it all occurred in a simulation.

After analyzing the data on the server, CloudSek experts determined that at least 20 people fell victim to Aur0ra, but were unable to find out how many of them were affected by the AI ​​attack. The AI ​​communication log covers the period from April 8 to May 21, 2026. Hackers compromised the resources of Belgian household chemicals maker Christeyns, German garage door manufacturer Teckentrup, Scottish helipad inspection agency Helideck Certification Agency, Argentinian pharmaceutical distributors, Italian manufacturers and Bayou Title, which positions itself as the largest real estate title insurance company in Louisiana.

Chat logs show the hacker issuing brief commands and the artificial intelligence agent Cursor providing suggestions to the chatbot in a typically cheerful manner. After detecting a vulnerable host on Teckentrup’s network, the AI ​​recommended exploits and hacks using known malicious tools, reporting a very high chance of success. The extent of hacking using Cursor cannot be determined. According to Gambit experts, the agent is controlled by the AI ​​model Anthropic Claude Sonnet 4.5.

Gambit emphasized that AI agents offer hackers some advantages by automating their work, estimating that they can move 30-50% faster than doing all the work manually. Cursor repeatedly refused to fulfill requests, calling them harmful or illegal, but the hackers always got around the denials and insisted that everything happened in a test environment. Cybersecurity experts believe the number of such incidents will increase.

If you find an error, select it with your mouse and press CTRL+ENTER.

Exit mobile version