Post by : Saif
Russian-speaking cybercriminals used Cursor, an AI coding assistant, to help conduct cyberattacks against a Belgian chemical company and at least six other businesses earlier this year, according to cybersecurity firm Gambit Security.
The findings highlight growing concerns about the use of commercial artificial intelligence tools by cybercriminals to speed up hacking operations and bypass security safeguards.
Gambit Security said it uncovered the campaign after finding an internet-exposed server linked to a newly identified ransomware group known as Aur0ra.
Security researchers were able to examine 28 chat sessions between the hackers and a Cursor AI agent.
According to Gambit's report, the hackers persuaded the AI system to assist with hundreds of potentially malicious activities by claiming that the work was part of a cybersecurity simulation or authorised test.
The conversations reportedly included requests for administrator accounts, passwords and other sensitive information.
Gambit did not initially identify the victims publicly, but information reviewed by Reuters allowed six companies to be identified.
Among the businesses reportedly targeted were Christeyns, a Belgian manufacturer of hygiene and cleaning products, and German garage door manufacturer Teckentrup.
Another identified victim was the Helideck Certification Agency in Scotland, which assesses helicopter landing sites.
The other targets included an Argentine pharmaceutical distributor, an Italian manufacturing company and Bayou Title, a Louisiana-based title insurance business.
At least one of the companies, Bayou Title, appeared on Aur0ra's data leak website, which can indicate that hackers attempted to pressure the company for a ransom.
The chat records showed that the hackers repeatedly presented their activities as a simulated security exercise.
This approach appeared to help them obtain assistance from the AI agent despite restrictions on harmful activity.
Gambit said the Cursor agent sometimes refused requests it considered illegal or dangerous. However, the hackers reportedly restarted conversations and repeated that their activities were part of a legitimate test.
According to the security firm, this allowed the attackers to continue receiving technical assistance.
Gambit executives said AI tools could significantly increase the speed at which cybercriminals conduct attacks.
Eyal Sela, the company's director of threat intelligence, said the AI assistant could potentially help attackers complete certain tasks much faster by reducing the amount of manual work involved.
The investigation also showed the AI agent providing technical suggestions during the attacks, including guidance related to vulnerable systems and password-related activities.
However, investigators could not independently determine how much the AI directly contributed to each individual breach or whether every targeted company experienced data theft or an attempted extortion.
Read more: SpaceX Shifts Focus From Mars to Moon Mission as 2027 Lunar Landing Target Emerges
The incident adds to wider concerns about the misuse of artificial intelligence.
AI coding assistants and autonomous agents can help legitimate developers write software, analyse systems and automate repetitive tasks. But similar capabilities can also potentially be abused by criminals.
Security researchers are increasingly warning that AI can reduce the technical barriers involved in certain cyberattacks by helping attackers analyse systems, write code and automate parts of an intrusion.
The case involving Aur0ra demonstrates how criminals may attempt to manipulate AI safeguards rather than directly disabling them.
Cursor is being incorporated into SpaceX following a deal involving the AI coding company behind the tool.
The development has increased attention on the security implications surrounding AI systems that can perform tasks with varying degrees of autonomy.
Cursor and SpaceX did not respond to requests for comment regarding the reported hacking campaign.
Anthropic, whose Claude model was reportedly used by the Cursor agent involved in the conversations, also did not provide a response.
Gambit described the situation as a continuing battle between AI developers and malicious users attempting to circumvent safety restrictions.
As AI agents become more capable of independently carrying out technical tasks, cybersecurity experts are increasingly focused on how these systems can distinguish legitimate security testing from criminal activity.
The Aur0ra case suggests that simply refusing individual harmful requests may not always be enough if attackers can repeatedly reframe their intentions or restart conversations.
#trending #latest #CyberSecurity #CyberAttack #AI #ArtificialIntelligence #CursorAI #SpaceX #CyberCriminals #Ransomware #Hacking #DataSecurity #TechNews #AIHacking #CyberThreats #DigitalSecurity #GlobalNews
Advances in Aerospace Technology and Commercial Aviation Recovery
Insights into breakthrough aerospace technologies and commercial aviation’s recovery amid 2025 chall
Defense Modernization and Strategic Spending Trends
Explore key trends in global defense modernization and strategic military spending shaping 2025 secu
Tens of Thousands Protest in Serbia on Anniversary of Deadly Roof Collapse
Tens of thousands in Novi Sad mark a year since a deadly station roof collapse that killed 16, prote
Canada PM Carney Apologizes to Trump Over Controversial Reagan Anti-Tariff Ad
Canadian PM Mark Carney apologized to President Trump over an Ontario anti-tariff ad quoting Reagan,
The ad that stirred a hornets nest, and made Canadian PM Carney say sorry to Trump
Canadian PM Mark Carney apologizes to US President Trump after a tariff-related ad causes diplomatic
Bengaluru-Mumbai Superfast Train Approved After 30-Year Wait
Railways approves new superfast train connecting Bengaluru and Mumbai, ending a 30-year demand, easi