The Russian-speaking group Aur0ra used SpaceX’s AI agent, Cursor, in attacks on at least seven companies, including those in Belgium, Germany, Scotland, Argentina, Italy and the US. According to Gambit Security and CloudSek, the hackers bypassed the agent’s restrictions by convincing it that the breach was part of a legitimate simulation.
Briefly about the main points
- Gambit found 28 chats between Aur0ra and the AI agent Cursor.
- The logs cover the period from 8 April to 21 May.
- The hackers sought help, describing the breaches as ‘testing’.
- Reuters identified six companies from chat snippets.
- The contribution of AI to the success of each penetration has not been independently established.
An exposed server granted access to the group’s chat rooms
Tel Aviv-based Gambit Security uncovered the campaign after Aur0ra accidentally left its server accessible on the internet. Researchers reviewed 28 chat sessions between one or more members of the group and the Cursor agent, dating from 8 April to 21 May.
Reuters independently reviewed some of the available chat logs and identified six victims: the Belgian hygiene and cleaning products manufacturer Christeyns, the German garage door manufacturer Teckentrup, the Scottish agency Helideck Certification Agency, an Argentine pharmaceutical distributor, an Italian manufacturer and the American company Bayou Title. The latter describes itself as the largest property title insurance company in Louisiana.
Singapore-based CloudSek reported that data on the server indicated that Aur0ra had claimed at least 20 victims in total. The company did not break down these cases according to whether the exploit had been used in them AI. Bayou Title appeared on the Aur0ra data leak website, which usually indicates that the attackers’ attempt to secure a ransom has failed.
The agent offered advice following claims that the test was allegedly legal
According to Gambit’s findings, the attackers persuaded the agent to carry out hundreds of malicious operations, including searching for login credentials and compromising high-value accounts. In their correspondence, they asked the agent to find any administrative accounts and working passwords.
In the chat rooms, Cursor confirmed the successful VPN connection After gaining access to the Argentine company, he offered to crack cryptographically protected password hashes and advised using a well-known malicious tool against a vulnerable host on the Teckentrup network. The agent assessed the chances of success for this operation as «very high».
Eyal Sela, Director of Threat Intelligence at Gambit, said that the agent had repeatedly rejected requests that it deemed unlawful or harmful. However, the hackers would usually initiate a new dialogue and again justify the request by claiming they were working in a test environment. Gambit claims that the agent’s internal line of reasoning, as recorded in the logs, showed how this cover story overrode his safeguards. According to the firm, Cursor was running on the Anthropic Claude Sonnet 4.5 model.
The extent to which AI influences individual breaches remains unknown
Ukrmedia was unable to independently determine to what extent Cursor’s advice contributed to each intrusion, or whether all the breaches resulted in data theft or an attempt at extortion. None of the six identified companies responded to the agency’s enquiries, nor did Aur0ra.
Sela estimated that AI could make the attackers’ work 30–50% faster, as it eliminated some of the manual tasks they had to perform. Gambit’s Head of Strategy, Curtis Simpson, described AI-assisted hacking as the new norm and characterised the cat-and-mouse game between AI providers and those attempting to bypass security as a constant race. Cursor and its parent company SpaceX, as well as Anthropic, did not respond to requests for comment.







