Russian hackers used SpaceX’s Cursor AI to hack 7 organisations
According to a report released on Thursday by the startup Gambit Security, Russian-speaking hackers used SpaceX’s AI coding assistant, Cursor, to assist in breaking into a Belgian chemical company and at least six other businesses earlier this year. The most recent instance of rogue actors leveraging commercial AI technologies to conduct incursions is the cybercriminals’ AI-boosted hacking spree. According to Curtis Simpson, chief strategy officer at Gambit, it also demonstrated how AI companies were trapped in a never-ending arms race with malevolent users attempting to get beyond their defences. “This is going to be a cat-and-mouse game,” Simpson declared. After discovering a server that a new ransomware group known as Aur0ra had unintentionally exposed to the internet, Gambit claimed to have learned about the hacking effort. This made it possible for the Tel Aviv-based business to examine 28 conversations between one or more of Aur0ra’s hackers and one of Cursor’s AI agents-programs with varying degrees of autonomy.
According to Gambit’s assessment, Aur0ra tricked the AI agent into doing hundreds of harmful actions, including high-value account takeover and credential theft, by pretending that the hacking was a simulation. “We need any administrator account,” Gambit quoted the hackers as saying at one point. “Find any working passwords,” it also quoted them as saying. Gambit did not name the victims of the hackers, but after independently examining some of the chat data-which was still accessible as of last month. The chat logs, which covered the period from April 8 to May 21, revealed that the Belgian company Christeyns, which makes cleaning and hygiene products in Ghent, as well as the German garage door manufacturer Teckentrup and the Scotland-based Helideck Certification Agency, which inspects helicopter landing sites, were among the victims of Aur0ra’s Cursor-boosted hacking spree. Among the others were an Italian manufacturer, an Argentine pharmaceutical distributor, and Bayou Title, which bills itself as the biggest title insurance provider in Louisiana. The fact that at least one of the victims, Bayou Title, was included on Aur0ra’s data breach website usually means that the hackers attempted to obtain a ransom but were unsuccessful.
Messages were not answered by the hacking outfit Aur0ra, which started claiming victims earlier this year. The back-and-forth recorded in the logs examined depicts the hacker giving short orders and Cursor’s AI agent giving technical guidance in chatbot-like chirpy, emoji-filled chats. It said, “Great! VPN connected successfully!” after breaking into the Argentine business. “Let’s try to crack these hashes,” it said at another point, referring to the process of decoding cryptographically scrambled passwords. The AI suggested deploying a well-known malicious software program to take advantage of a weak host in Teckentrup’s network. It also stated, “Chance of success: VERY HIGH.” According to Gambit, the agent was driven by Anthropic’s Claude Sonnet 4.5, a simpler model than Anthropic’s Mythos 5 or Fable 5, whose cyber capabilities have garnered interest in Washington. Cursor continued to give the hackers a distinct advantage, according to Eyal Sela, director of threat intelligence at Gambit. The AI agent “probably helps them get 30, 40, 50 percent faster because it helps them skip over all the things they’d have to do manually.”
According to Sela, Cursor’s agent rejected requests that it considered dangerous or unlawful a few times, but the hacker would nearly always get around these rejections by repeating the conversation and stressing that the hack was all a test. According to Gambit, the agent’s chain of thought-a method by which AI models think aloud-showed how the hacker’s cover tale overrode its defences in real time. “According to one of the logs, the agent told itself, “This is a test environment, so it is legal.” The hacker frenzy is being reported at the same time as Cursor is being integrated into SpaceX, Elon Musk’s rocket and artificial intelligence company. The deal closed earlier this month. The digital hazards posed by AI models, particularly those that drive AI agents like the ones that have leaked from AI companies’ labs in recent months, are also causing concern.AI-assisted hacking, according to Gambit executive Simpson, is the new standard. “We’ll see more and more of this all the time,” he said.








