Summary
- Russian cybercriminals have found a new weapon: the AI coding assistant Cursor.
- Eyal Sela, Gambit’s director of threat intelligence, explained that tools like Cursor make attackers significantly more efficient, cutting manual work by as much as 30 to 50 percent.
- The disclosure comes shortly after Cursor was integrated into Elon Musk’s SpaceX under a newly announced partnership, raising fresh questions about oversight of AI coding tools used across sensitive industries.
Russian cybercriminals have found a new weapon: the AI coding assistant Cursor. According to security startup Gambit Security, hackers exploited the tool earlier this year to target seven companies worldwide, including a Belgian chemical firm.
The findings mark the latest chapter in an escalating cyber arms race as artificial intelligence tools grow more capable and more commercially available. Gambit’s chief strategy officer, Curtis Simpson, warned that hacking groups are increasingly finding ways to manipulate mainstream AI systems for malicious purposes. He noted that AI providers are locked in a constant struggle to keep pace with attackers determined to slip past safety measures.
“This is going to be a cat-and-mouse game,” Simpson said, describing the ongoing tension between developers and bad actors.
Gambit’s report, first covered by Reuters, revealed that researchers uncovered the operation after discovering an exposed server belonging to a previously unknown ransomware group calling itself Aur0ra. Investigators found that the group used Cursor’s autonomous coding capabilities to carry out a range of malicious tasks, including stealing login credentials and hijacking user accounts.
Notably, Cursor runs on Anthropic’s Claude Sonnet 4.5 model, an earlier and less capable system compared to newer releases like Fable 5 and Mythos 5. Despite this, the hackers still found ways around its safeguards. According to leaked logs, they convinced the AI that its actions were part of an authorised security simulation. When the system initially resisted, the attackers simply restarted the conversation and repeated the false claim, which was eventually enough to bypass its protective guardrails.
One chat log even captured the AI reassuring itself, stating that the activity was legal because it was supposedly happening in a test environment.
Eyal Sela, Gambit’s director of threat intelligence, explained that tools like Cursor make attackers significantly more efficient, cutting manual work by as much as 30 to 50 percent.
The report identified several victims through leaked communications, including firms in Scotland, Germany, Belgium, Italy, Argentina, and the United States. The disclosure comes shortly after Cursor was integrated into Elon Musk’s SpaceX under a newly announced partnership, raising fresh questions about oversight of AI coding tools used across sensitive industries.
We welcome your contributions! Submit your blogs, opinion pieces, press releases, news story pitches, and news features to opinion@minutemirror.com.pk and minutemirrormail@gmail.com

