Published 9 hours ago • loading... • Updated 1 hour ago
Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies
Researchers say the hackers used Cursor to automate credential theft and account takeovers, and they traced ransom payments across the operation.
On Thursday, Russian-speaking hackers known as Aur0ra used SpaceX's Cursor AI assistant to breach at least seven companies across Belgium, Argentina, and the United States, according to Reuters and Gambit Security reporting.
Tel Aviv-based Gambit Security discovered the campaign after finding an exposed server containing 28 chat sessions between Aur0ra hackers and the AI agent, providing researchers an unusually detailed view of the group's operations.
Hackers manipulated the AI by falsely claiming malicious actions were part of a 'simulation,' bypassing safety guardrails to execute hundreds of credential theft and account takeover operations. The agent told itself, 'This is a test environment, so it is legal.'
Gambit threat intelligence director Eyal Sela said the AI agent likely accelerated attacks by '30, 40, 50 percent,' while chief strategy officer Curtis Simpson characterized the struggle as a 'cat-and-mouse game.'
The campaign emerged as Cursor integrated into SpaceX following a deal closed earlier this month, highlighting rising security concerns about AI models and digital risks posed by autonomous agents.
They used the programming assistant with artificial intelligence to speed up attacks and violate companies from different countries, including an Argentine pharmaceutical distributor
The hackers convinced the artificial intelligence agent that it was participating in a simulation, when in reality it was a cyberattack. The post “Russian-speaking cybercriminals” hacked 7 companies by tricking SpaceX’s AI tool appeared first on in.gr.