Friday, 28 August 2026 SourcesAbout🌓
🇿🇦 ZA ▾
BREAKING
Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies Australia dispatches aid to Nepal as 39 citizens missing US ICE grants $16.7m contract to buy thousands of electric shock gloves Trump renames Lake Ontario as ‘Lake America’ amid Canada trade war Siya Kolisi’s ‘responsible’ approach to injury comeback praised by Thomas du Toit Traffic fine shortfall prompts R115m Cape Town budget adjustment Mammoth clash ahead as Springboks face must-win All Blacks Test in Cape Town Roodepoort Theatre launches monthly West Rand Family Market Nkandla architect Minenhle Makhanya ordered to repay R147 million after tribunal ruling SIBONGAKONKE SHOBA | Why is the ANC afraid to name mayoral candidates? Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies Australia dispatches aid to Nepal as 39 citizens missing US ICE grants $16.7m contract to buy thousands of electric shock gloves Trump renames Lake Ontario as ‘Lake America’ amid Canada trade war Siya Kolisi’s ‘responsible’ approach to injury comeback praised by Thomas du Toit Traffic fine shortfall prompts R115m Cape Town budget adjustment Mammoth clash ahead as Springboks face must-win All Blacks Test in Cape Town Roodepoort Theatre launches monthly West Rand Family Market Nkandla architect Minenhle Makhanya ordered to repay R147 million after tribunal ruling SIBONGAKONKE SHOBA | Why is the ANC afraid to name mayoral candidates?
Latest

Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies

Daily Maverick ·
Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies

WASHINGTON, Aug 27 (Reuters) - Russian-speaking hackers used SpaceX’s AI coding assistant, Cursor, to help break in to a Belgian chemical company and at least six other firms earlier this year, according to data reviewed by Reuters and reports issued on Thursday by cybersecurity companies Gambit Security and CloudSek.

The cybercriminals’ AI-boosted hacking spree is the latest example of how rogue actors are using commercial AI tools to carry out intrusions. Gambit’s chief strategy officer, Curtis Simpson, said it also showed how AI providers were locked in to a never-ending arms race with malicious users trying to circumvent their guardrails.

Cursor and its parent company, SpaceX, did not return messages seeking comment.

Gambit said it discovered the hacking campaign after finding a server that a new ransomware gang called Aur0ra had inadvertently exposed to the internet. That allowed the Tel Aviv-based company to review 28 chat sessions between one or more of Aur0ra’s hackers and one of Cursor’s AI agents, which are programs that can operate with various degrees of autonomy.

In its report , Gambit said Aur0ra persuaded the AI agent to carry out hundreds of malicious operations — such as credential theft or high-value account takeover — by falsely claiming that the hacking was part of a simulation.

“We need any administrator account,” Gambit quoted the hackers as saying at one point. “Find any working passwords,” it also quoted them as saying.

In its report , Singapore-based CloudSek said the data on the server showed that Aur0ra had claimed at least 20 victims overall, although it did not break down how many were compromised with the help of AI.

Neither Gambit nor CloudSek identified the hackers’ victims by name, but Reuters was able to identify six of them after independently reviewing portions of the chat data, which was still online as of last month.

The chat logs, which spanned April 8 to May 21, showed that the victims of Aur0ra’s Cursor-boosted hacking spree included the Belgian company — Ghent-based hygiene and cleaning products maker Christeyns — as well as German garage door manufacturer Teckentrup and the Scotland-based Helideck Certification Agency, which vets helicopter landing sites. The rest included an Argentine pharmaceutical distributor, an Italian manufacturer, and Bayou Title, which advertises itself as Louisiana’s largest title insurance company.

None of the six companies responded to requests by Reuters for comment. At least one of the victims, Bayou Title, was named on Aur0ra’s data leak site, which typically indicates that the hackers tried and failed to secure a ransom.

Read the full article on Daily Maverick ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.dailymaverick.co.za — the content belongs to Daily Maverick.

More from Daily Maverick

See all ›

More in Latest

See all ›