Published 23 hours ago • loading... • Updated 3 hours ago
Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies
Gambit Security said the hackers used Cursor to automate credential theft and account takeovers, speeding some intrusions by 30% to 50%.
On Thursday, Gambit Security revealed that Russian-speaking hackers from the group Aur0ra used the AI coding assistant Cursor to facilitate cyber intrusions against at least seven companies between April and May.
Gambit discovered the campaign after finding an exposed server containing 28 chat logs showing attackers circumventing AI safety guardrails by falsely claiming their malicious operations were part of a "simulation" or "test environment."
The AI agent, powered by Anthropic's Claude Sonnet, helped hackers skip manual steps, increasing their operational speed by 30% to 50% while they deployed tools like BloodHound and Impacket to steal credentials.
Investigators identified victims including Christeyns and Bayou Title, with attacks concluding before Cursor's parent company was acquired by SpaceX in August, clarifying the software was not SpaceX-owned during the spree.
Coinciding with an open letter from 100 companies, experts warn this incident highlights the persistent challenge of securing AI models against misuse as AI-enabled cyber attacks proliferate in coming months.
"Cursor is supposed to help programmers, but SpaceX's AI assistant can also be a tool for hackers – if they unleash it. At least one German company was among those attacked.
They used the programming assistant with artificial intelligence to speed up attacks and violate companies from different countries, including an Argentine pharmaceutical distributor