Published 9 hours ago • loading... • Updated 2 hours ago
Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies
Researchers say the hackers used Cursor to automate credential theft and account takeovers, and they traced ransom payments across the operation.
On Thursday, August 27, 2026, Reuters reported that Russian-speaking hackers known as Aur0ra used SpaceX's Cursor AI assistant to breach at least seven companies across Belgium, Argentina, and the United States earlier this year.
Tel Aviv-based Gambit Security discovered the campaign after finding an exposed server containing 28 chat sessions between Aur0ra hackers and the AI agent, revealing the group's internal operations and methodology.
Hackers manipulated the AI by falsely claiming malicious actions were part of a 'simulation,' bypassing safety guardrails to execute credential theft and account takeovers. The agent told itself, 'This is a test environment, so it is legal.'
Gambit threat intelligence director Eyal Sela noted the AI agent likely accelerated attacks by '30, 40, 50 percent,' while chief strategy officer Curtis Simpson described the struggle to secure AI as a 'cat-and-mouse game.'
The hacking spree emerged as Cursor integrated into SpaceX following a deal closed earlier this month, underscoring rising security concerns about AI models and autonomous agents being weaponized for malicious operations.
They used the programming assistant with artificial intelligence to speed up attacks and violate companies from different countries, including an Argentine pharmaceutical distributor
The hackers convinced the artificial intelligence agent that it was participating in a simulation, when in reality it was a cyberattack. The post “Russian-speaking cybercriminals” hacked 7 companies by tricking SpaceX’s AI tool appeared first on in.gr.