A Russian-speaking ransomware operator used Cursor’s built-in AI coding agent to help breach at least seven companies across three continents, according to an investigation by Israeli cybersecurity firm Gambit Security first reported by Reuters on Aug. 27.
The breaches took place between April 8 and May 21, when an affiliate of the Aur0ra ransomware group used Cursor’s AI agent during hands-on activity inside victim networks, based on 28 chat sessions Gambit recovered from an exposed command-and-control server.
Gambit said the operator already had credentials or network access before invoking the AI agent. The tool then sped up credential theft, privilege escalation, network scanning and VPN configuration that otherwise would have been done manually.
The bypass relied on social engineering rather than a software exploit. When the agent, which was running on Anthropic’s Claude Sonnet 4.5 at the time, refused a request, the operator restarted the conversation and reframed the activity as an authorized security test until the agent complied.
Gambit’s threat intelligence director Eyal Sela estimated the AI made the attackers “30, 40, 50 percent faster” than manual operation.
Reuters independently confirmed at least seven successful breaches. Named victims included Belgian hygiene manufacturer Christeyns, German garage door maker Teckentrup, Scotland’s Helideck Certification Agency and Louisiana-based Bayou Title, along with an unnamed Argentine pharmaceutical distributor and an unnamed Italian manufacturer.
The findings came four months after Five Eyes cyber agencies published guidance on agentic AI services. On May 1, CISA, the NSA and cyber authorities in Australia, Canada, New Zealand and the United Kingdom issued “Careful Adoption of Agentic AI Services,” listing 23 risks across five categories and calling for AI agents to be treated as distinct principals with cryptographically anchored identities and short-lived credentials.
Cloud Security Alliance researchers now cite the Cursor case directly as validation of that framework.
The case also adds pressure on Cursor’s parent company Anysphere, which SpaceX acquired earlier in 2026. On Aug. 28, OpenAI said it would remove its models from Cursor by Nov. 12, citing distrust in SpaceX’s willingness to honor contractual terms.
OpenAI said the decision was tied to its forthcoming Astra model and access-control concerns around near-frontier AI capabilities. Cursor co-founder Michael Truell said OpenAI models accounted for about 5% of Cursor’s AI traffic.
The governance frameworks from CISA and NIST’s AI Agent Standards Initiative, launched in February 2026, remain advisory rather than legally binding, but enterprise procurement and cyber insurance processes are beginning to reference them.
Click Here For The Original Source.
