Incident2026-08-27

Security firms Gambit Security and CloudSek reported that a Russian-speaking ransomware group called Aur0ra used the Cursor coding assistant to help break into a Belgian chemical maker and at least six other companies. The hackers got around the tool's safety refusals by claiming the intrusions were a test, and researchers found the evidence on a server the group left exposed. Reuters could not establish how much of each break-in the AI actually enabled.

What changed

Earlier reports of criminals abusing AI assistants centred on chatbots rather than coding agents doing the intrusion work.

  • 28 chat sessions reviewed
  • at least 20 claimed victims
  • logs span 8 April to 21 May
  • 30-50% faster, per researcher

Send this to someone who needs it

Shares the story and its sources. Nothing about you.

What does this mean for your job?

This is the story as everyone gets it. Once a week we send you the version written for your role — what changed, why it matters for the work you actually do, and one thing to try. Free while we tune it.