AI coding agent as a tool for real attacks

Hackers Used AI Assistant Cursor for Attacks on Corporate Networks

Vulnerabilities, Cursor, CVE-2026-50548, CVE-2026-50549, critical Cursor vulnerabilities explained, Cursor sandbox escape vulnerability, Cursor Vulnerabilities, Sandbox Escape
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: aileenchik/Shutterstock.com

An investigation shows how the extortion group Aur0ra used Cursor to exploit already compromised corporate networks.

According to its own statements, Gambit Security was able to evaluate 28 publicly accessible chat sessions as well as additional infrastructure of the group, thereby gaining direct insight into the actual use of the AI agent during real attacks. The hackers deployed a Cursor agent powered by Anthropic’s Claude Sonnet 4.5 model in so-called thinking mode, initially handing over previously stolen credentials or initial access to the respective target network before assigning it regular exploitation tasks.

Ad

These included internal network scans, listing existing permissions, credential attacks, NTLM relay attempts, and certificate-based attacks. For some tasks, the attackers specified concrete tools or techniques for the agent, while for others, it merely received a target and full freedom in choosing the approach. If a command failed, Cursor independently adjusted it or suggested alternative approaches tailored to the respective target environment, sometimes even in the form of numbered selection lists from which the attackers merely had to select an option.

In a first documented attack vector, the hackers deployed a Linux variant of their own ransomware specifically against VMware ESXi environments. A second attack vector, also attributed to Aur0ra with medium confidence, targeted eight organizations in Israel, Germany, Austria, Spain, the US, and Argentina, using a self-hosted, S3-compatible storage infrastructure for data exfiltration. Reuters independently identified several affected parties, including the Belgian cleaning products manufacturer Christeyns, the German door manufacturer Teckentrup, the Scottish Helideck Certification Agency, and the Louisiana-based company Bayou Title. On Aur0ra’s own darknet leak site, 31 victims are currently listed, including larger international companies such as Sumitomo Electric Bordnetze, Corporación Primax, and ALS Global.

Refusals bypassed by simply claiming a test

According to Gambit, Cursor initially rejected individual requests as potentially malicious or illegal. However, these guardrails were comparatively easy to bypass: Eyal Sela, Director of Threat Intelligence at Gambit, explained to Reuters that the hackers almost always bypassed refusals by emphasizing that it was a test. Max Gannon, Cyber Intelligence Team Manager at security firm Cofense, framed the trick for Cybernews as follows: The attackers simply told the agent the hack was a test, whereupon it convinced itself of this framing and even assumed a test environment made the activity legally permissible. Gannon described this as a reminder that guardrails directed against malicious keywords or requests can still be undermined by a convincingly framed narrative.

Ad

The attackers explicitly forbade the agent from performing certain particularly risky actions, such as DCSync attacks, locking out user credentials, or creating new computer objects within compromised domains. According to Sela’s assessment, the use of Cursor accelerated the actual attacks by around 30 to 50 percent, as a significant portion of the otherwise manually required work steps was taken off the attackers’ hands.

Cursor now part of SpaceX

Cursor was originally developed by the startup Anysphere and can be operated with several major AI models, including Claude, GPT, Gemini, and Grok. On August 14, the company was officially acquired by Elon Musk’s space company SpaceX; the attacks described here took place prior to this acquisition. Gambit emphasizes that the actual extent of Cursor’s role in each individual breach observed cannot ultimately be determined with absolute certainty.

(Editorial Team)

Ad

Weitere Artikel