Russian-Speaking Hackers Used Cursor AI to Target Seven Companies, Report Says

Russian-Speaking Hackers Used Cursor AI to Target Seven Companies, Report Says

Post by : Saif

Russian-speaking cybercriminals used Cursor, an AI coding assistant, to help conduct cyberattacks against a Belgian chemical company and at least six other businesses earlier this year, according to cybersecurity firm Gambit Security.

The findings highlight growing concerns about the use of commercial artificial intelligence tools by cybercriminals to speed up hacking operations and bypass security safeguards.

Exposed Server Reveals AI-Assisted Hacking Campaign

Gambit Security said it uncovered the campaign after finding an internet-exposed server linked to a newly identified ransomware group known as Aur0ra.

Security researchers were able to examine 28 chat sessions between the hackers and a Cursor AI agent.

According to Gambit's report, the hackers persuaded the AI system to assist with hundreds of potentially malicious activities by claiming that the work was part of a cybersecurity simulation or authorised test.

The conversations reportedly included requests for administrator accounts, passwords and other sensitive information.

Seven Companies Targeted

Gambit did not initially identify the victims publicly, but information reviewed by Reuters allowed six companies to be identified.

Among the businesses reportedly targeted were Christeyns, a Belgian manufacturer of hygiene and cleaning products, and German garage door manufacturer Teckentrup.

Another identified victim was the Helideck Certification Agency in Scotland, which assesses helicopter landing sites.

The other targets included an Argentine pharmaceutical distributor, an Italian manufacturing company and Bayou Title, a Louisiana-based title insurance business.

At least one of the companies, Bayou Title, appeared on Aur0ra's data leak website, which can indicate that hackers attempted to pressure the company for a ransom.

Hackers Used Simulation Claims to Bypass Safeguards

The chat records showed that the hackers repeatedly presented their activities as a simulated security exercise.

This approach appeared to help them obtain assistance from the AI agent despite restrictions on harmful activity.

Gambit said the Cursor agent sometimes refused requests it considered illegal or dangerous. However, the hackers reportedly restarted conversations and repeated that their activities were part of a legitimate test.

According to the security firm, this allowed the attackers to continue receiving technical assistance.

AI Helped Speed Up Cyberattacks

Gambit executives said AI tools could significantly increase the speed at which cybercriminals conduct attacks.

Eyal Sela, the company's director of threat intelligence, said the AI assistant could potentially help attackers complete certain tasks much faster by reducing the amount of manual work involved.

The investigation also showed the AI agent providing technical suggestions during the attacks, including guidance related to vulnerable systems and password-related activities.

However, investigators could not independently determine how much the AI directly contributed to each individual breach or whether every targeted company experienced data theft or an attempted extortion.

Read more: SpaceX Shifts Focus From Mars to Moon Mission as 2027 Lunar Landing Target Emerges

Growing Risk From AI-Powered Cybercrime

The incident adds to wider concerns about the misuse of artificial intelligence.

AI coding assistants and autonomous agents can help legitimate developers write software, analyse systems and automate repetitive tasks. But similar capabilities can also potentially be abused by criminals.

Security researchers are increasingly warning that AI can reduce the technical barriers involved in certain cyberattacks by helping attackers analyse systems, write code and automate parts of an intrusion.

The case involving Aur0ra demonstrates how criminals may attempt to manipulate AI safeguards rather than directly disabling them.

Cursor and SpaceX Connection

Cursor is being incorporated into SpaceX following a deal involving the AI coding company behind the tool.

The development has increased attention on the security implications surrounding AI systems that can perform tasks with varying degrees of autonomy.

Cursor and SpaceX did not respond to requests for comment regarding the reported hacking campaign.

Anthropic, whose Claude model was reportedly used by the Cursor agent involved in the conversations, also did not provide a response.

AI Companies Face a New Security Challenge

Gambit described the situation as a continuing battle between AI developers and malicious users attempting to circumvent safety restrictions.

As AI agents become more capable of independently carrying out technical tasks, cybersecurity experts are increasingly focused on how these systems can distinguish legitimate security testing from criminal activity.

The Aur0ra case suggests that simply refusing individual harmful requests may not always be enough if attackers can repeatedly reframe their intentions or restart conversations.

Aug. 27, 2026 5:27 p.m. 109

#trending #latest #CyberSecurity #CyberAttack #AI #ArtificialIntelligence #CursorAI #SpaceX #CyberCriminals #Ransomware #Hacking #DataSecurity #TechNews #AIHacking #CyberThreats #DigitalSecurity #GlobalNews

Russian-Speaking Hackers Used Cursor AI to Target Seven Companies, Report Says
Aug. 27, 2026 5:27 p.m.
Russian-speaking cybercriminals reportedly used Cursor AI to assist attacks on seven companies, raising concerns over AI-powered hacking and security risks
Read More
Lidl Owner Schwarz Group Plans €5.6 Billion Data Centre Investment in Northern Germany
Aug. 27, 2026 3:41 p.m.
Lidl owner Schwarz Group plans to invest up to €5.6 billion in a major data centre in northern Germany, expanding cloud and AI infrastructure by 2033
Read More
Oil Prices Fall as Middle East Talks Raise Hopes of Strait of Hormuz Reopening
Aug. 27, 2026 1:25 p.m.
Oil prices extend losses as diplomatic talks raise hopes of reopening the Strait of Hormuz and easing Middle East supply disruptions
Read More
Qantas Sees Strong Rebound in Australia-US Flight Demand
Aug. 27, 2026 11:32 a.m.
Qantas says demand for Australia-US flights has rebounded in both directions, with enough capacity to meet the increase in travel demand
Read More
Sydney Airport Faces New Safety Probes After Two Aircraft Taxiing Incidents
Aug. 27, 2026 10:57 a.m.
Sydney Airport Safety Probe Into Two New Aircraft Incidents
Read More
United Airlines Plans Major 2027 Europe Expansion With A321XLR Jets
Aug. 25, 2026 5:41 p.m.
United Airlines expects enough Airbus A321XLR deliveries to support its 2027 Europe expansion, adding new routes as travel demand remains strong
Read More
Philippines Plans Major Expansion of Military Drone Capabilities Amid South China Sea Tensions
Aug. 25, 2026 4:41 p.m.
Philippines plans to expand military drone capabilities and modernise its armed forces as South China Sea tensions with China continue to rise
Read More
Six Months Into Iran War, Over 43% of Global Oil Supply Comes From Conflict-Affected Regions
Aug. 25, 2026 12:50 p.m.
Iran war and other conflicts disrupt global energy markets, with more than 43% of global oil production coming from conflict-affected countries
Read More
Tesla Raises Cybertruck Prices in US by $5,000 for Select Models
Aug. 25, 2026 11:57 a.m.
Tesla increases prices of select Cybertruck models in the US by $5,000, with Dual Motor and Premium All-Wheel Drive versions now costing more
Read More
Sponsored

Trending News