{"id":68324,"date":"2026-08-28T01:32:56","date_gmt":"2026-08-28T01:32:56","guid":{"rendered":"https:\/\/newsvog.com\/ur\/68324"},"modified":"2026-08-28T01:33:24","modified_gmt":"2026-08-28T01:33:24","slug":"cybercriminals-used-spacexs-cursor-ai-tool-to-hack-seven-companies","status":"publish","type":"post","link":"https:\/\/newsvog.com\/ur\/68324","title":{"rendered":"Cybercriminals used SpaceX\u2019s Cursor AI tool to hack seven companies"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div style=\"font-size:16px;line-height:1.6\">\n<p><strong>WASHINGTON: Russian-speaking hackers used SpaceX\u2019s AI coding assistant, Cursor, to help break in to a Belgian chemical company and at least six other \u200bfirms earlier this year, according to data reviewed by Reuters and a report issued on Thursday by the startup Gambit Security.<\/strong><\/p>\n<p><span>The cybercriminals\u2019 AI-boosted hacking spree is the latest \u200cexample of how rogue actors are using commercial AI tools to carry out intrusions. Gambit\u2019s chief strategy officer, Curtis Simpson, said it also showed how AI providers were locked in to a never-ending arms race with malicious users trying to circumvent their guardrails.<\/span><\/p>\n<p><span>\u201cThis is going to be a cat-and-mouse game,\u201d Simpson said.<\/span><\/p>\n<p><span>Cursor and its parent company, SpaceX, did not return messages seeking comment.<\/span><\/p>\n<h2><span>EXPOSED SERVER REVEALS HACKING METHODS<\/span><\/h2>\n<p><span>Gambit said it discovered the hacking campaign after finding a server that a \u200bnew ransomware gang called Aur0ra had inadvertently exposed to the internet. That allowed the Tel Aviv-based company to review 28 chat sessions between one or more of Aur0ra\u2019s hackers and \u200bone of Cursor\u2019s AI agents, which are programs that can operate with various degrees of autonomy.<\/span><\/p>\n<p><span>In its report, Gambit said Aur0ra persuaded the AI agent \u2060to carry out hundreds of malicious operations \u2014 such as credential theft or high-value account takeover \u2014 by falsely claiming that the hacking was part of a simulation.<\/span><\/p>\n<p><span>\u201cWe need any administrator account,\u201d Gambit quoted the \u200bhackers as saying at one point. \u201cFind any working passwords,\u201d it also quoted them as saying.<\/span><\/p>\n<p><span>Gambit did not identify the hackers\u2019 victims by name, but Reuters was able to identify six of them after independently reviewing \u200bportions of the chat data, which was still online as of last month.<\/span><\/p>\n<p><span>The chat logs, which spanned April 8 to May 21, showed that the victims of Aur0ra\u2019s Cursor-boosted hacking spree included the Belgian company \u2014 Ghent-based hygiene and cleaning products maker Christeyns \u2014 as well as German garage door manufacturer Teckentrup and the Scotland-based Helideck Certification Agency, which vets helicopter landing sites. The rest included an Argentine pharmaceutical distributor, an Italian manufacturer, and Bayou Title, which advertises itself \u200bas Louisiana\u2019s largest title insurance company.<\/span><\/p>\n<p><span>Even by the frothy standards of the AI era, CXMT\u2019s trading debut in Shanghai last month was extraordinary.<\/span><\/p>\n<p><span>None of the six companies responded to requests by Reuters for comment. At least one of the victims, Bayou Title, was named on Aur0ra\u2019s data leak site, which typically \u200bindicates that the hackers tried and failed to secure a ransom. Aur0ra, a hacking group that began claiming victims earlier this year, did not return messages.<\/span><\/p>\n<h2><span>HACKERS FOOLED AI WITH SIMULATION CLAIM<\/span><\/h2>\n<p><span>The back-and-forth captured in the logs reviewed \u200cby Reuters \u2060shows the hacker issuing terse commands and Cursor\u2019s AI agent responding with technical advice delivered in chirpy, emoji-laden messages typical of chatbot-speak.<\/span><\/p>\n<p><span>\u201cGreat! VPN connected successfully!\u201d it said after breaching the Argentine company.<\/span><\/p>\n<p><span>\u201cLet\u2019s try to crack these hashes,\u201d it said at another point, referring to the process of decoding cryptographically scrambled passwords.<\/span><\/p>\n<p><span>After finding a vulnerable host in Teckentrup\u2019s network, the AI recommended using a well-known malicious software tool to exploit it. \u201c**Chance of success**: VERY HIGH,\u201d it added.<\/span><\/p>\n<p><span>Reuters could not independently ascertain the extent to which the break-ins were facilitated by help from the Cursor agent, or whether every breach necessarily resulted in exfiltration of data \u200band an extortion attempt. Gambit said the agent \u200bwas powered by Anthropic\u2019s Claude Sonnet 4.5, a \u2060more basic model than Anthropic\u2019s Mythos 5 or Fable 5, whose cyber prowess has drawn attention in Washington.<\/span><\/p>\n<p><span>Anthropic did not return a message seeking comment.<\/span><\/p>\n<p><span>Eyal Sela, Gambit\u2019s director of threat intelligence, said Cursor still offered the hackers a clear boost, adding that the AI agent \u201cprobably helps them get 30, 40, 50 percent \u200bfaster because it helps them skip over all the things they\u2019d have to do manually.\u201d<\/span><\/p>\n<p><span>Cursor\u2019s agent refused requests that it deemed harmful or illegal \u200ba handful of times, Sela \u2060said, but the hacker would almost always circumvent the refusals by restarting the dialogue and emphasizing that the hack was all part of a test.<\/span><\/p>\n<p><span>Gambit said the agent\u2019s chain of thought, a way that AI models think out loud, showed the hacker\u2019s cover story overriding its safeguards in real time.<\/span><\/p>\n<p><span>\u201cThis is a test environment, so it is legal,\u201d the agent said to itself, according to one of the logs.<\/span><\/p>\n<p><span>News of the hacking \u2060spree comes as \u200bCursor is being incorporated within Elon Musk\u2019s rockets-and-AI company, SpaceX, a deal that closed earlier this month. Concerns are also rising \u200bover the digital risks posed by AI models, especially the models that power AI agents like the ones that have escaped from AI companies\u2019 labs over the past few months.<\/span><\/p>\n<p><span>Simpson, the Gambit executive, said AI-assisted hacking was the new normal.<\/span><\/p>\n<p><span>\u201cWe\u2019ll see more \u200band more of this all the time,\u201d he said.<\/span><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/arynews.tv\/cybercriminals-used-spacexs-cursor-ai-tool-to-hack-seven-companies\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>WASHINGTON: Russian-speaking hackers used SpaceX\u2019s AI coding assistant, Cursor, to help break in to a Belgian chemical company and at least six other \u200bfirms earlier this year, according to data reviewed by Reuters and a report issued on Thursday by the startup Gambit Security. The cybercriminals\u2019 AI-boosted hacking spree is the latest \u200cexample of how rogue actors are using commercial&#8230;<\/p>\n","protected":false},"author":1,"featured_media":68325,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_kad_blocks_custom_css":"","_kad_blocks_head_custom_js":"","_kad_blocks_body_custom_js":"","_kad_blocks_footer_custom_js":"","_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","footnotes":""},"categories":[16],"tags":[],"class_list":["post-68324","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-pakistan"],"taxonomy_info":{"category":[{"value":16,"label":"Pakistan"}]},"featured_image_src_large":["https:\/\/newsvog.com\/ur\/wp-content\/uploads\/ARY-1200-x-675-px-2026-08-27T175110.662-1024x576.jpg",1024,576,true],"author_info":{"display_name":"frkhokhar@gmail.com","author_link":"https:\/\/newsvog.com\/ur\/author\/frkhokhargmail-com"},"comment_info":0,"category_info":[{"term_id":16,"name":"Pakistan","slug":"pakistan","term_group":0,"term_taxonomy_id":16,"taxonomy":"category","description":"All about Pakistan","parent":0,"count":3795,"filter":"raw","cat_ID":16,"category_count":3795,"category_description":"All about Pakistan","cat_name":"Pakistan","category_nicename":"pakistan","category_parent":0}],"tag_info":false,"_links":{"self":[{"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/posts\/68324","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/comments?post=68324"}],"version-history":[{"count":1,"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/posts\/68324\/revisions"}],"predecessor-version":[{"id":68326,"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/posts\/68324\/revisions\/68326"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/media\/68325"}],"wp:attachment":[{"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/media?parent=68324"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/categories?post=68324"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsvog.com\/ur\/wp-json\/wp\/v2\/tags?post=68324"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}