Security firms Gambit Security and CloudSek reported that a Russian-speaking ransomware group called Aur0ra used the Cursor coding assistant to help break into a Belgian chemical maker and at least six other companies. The hackers got around the tool's safety refusals by claiming the intrusions were a test, and researchers found the evidence on a server the group left exposed. Reuters could not establish how much of each break-in the AI actually enabled.
What changed
Earlier reports of criminals abusing AI assistants centred on chatbots rather than coding agents doing the intrusion work.
- 28 chat sessions reviewed
- at least 20 claimed victims
- logs span 8 April to 21 May
- 30-50% faster, per researcher
Sources