Key takeaways

  • WASHINGTON: Russian-speaking hackers used SpaceX's AI coding assistant, Cursor, to help break in to a Belgian chemical company and at least…
  • The cybercriminals' AI-boosted hacking spree is the latest example of how rogue actors are using commercial AI ​tools to carry out…
  • EXPOSED SERVER REVEALS HACKING METHODSGambit said it discovered the hacking campaign after finding a server that a ‌new ransomware gang…

What happened

The cybercriminals' AI-boosted hacking spree is the latest example of how rogue actors are using commercial AI ​tools to carry out intrusions. Gambit's chief strategy officer, Curtis Simpson, said it also showed how AI providers were locked in to a never-ending arms race with malicious users trying to circumvent their guardrails.

​The rest included an Argentine ​pharmaceutical distributor, an Italian manufacturer, and Bayou Title, which advertises itself as Louisiana's largest title insurance company. None of the six companies responded ⁠to requests by Reuters for comment. At least one of the victims, Bayou Title, was named on Aur0ra's ​data leak site, which typically indicates that the hackers tried and failed to secure a ransom. "Great!

Why it matters

EXPOSED SERVER REVEALS HACKING METHODSGambit said it discovered the hacking campaign after finding a server that a ‌new ransomware gang called ⁠Aur0ra had inadvertently ⁠exposed to the internet. That allowed the Tel Aviv-based company to review 28 chat sessions between one or more of Aur0ra's hackers and one of Cursor's AI agents, which are programs that can operate with various degrees of ​autonomy.

In its report, Gambit said Aur0ra persuaded the AI agent to carry out hundreds of malicious operations - such as credential theft or high-value account takeover - by falsely claiming that the hacking was ​part of a simulation. "We need any administrator account," Gambit quoted the hackers as saying at one point. "Find any working passwords," it also quoted them as saying.

The chat ​logs, which spanned April 8 to May 21, showed that the victims of Aur0ra's Cursor-boosted hacking spree included the Belgian ⁠company - Ghent-based ‌hygiene and cleaning products maker Christeyns - as well as German garage door manufacturer Teckentrup and the Scotland-based Helideck Certification Agency, which vets helicopter landing sites.

What to watch

" it said after breaching the Argentine company. After finding a vulnerable host in Teckentrup's network, the AI recommended using a well-known malicious software tool to exploit it. Reuters could not independently ascertain the extent to which the break-ins were facilitated by help from the Cursor agent, or whether every ‌breach necessarily resulted in exfiltration of data and an extortion attempt.

5, a more basic model than Anthropic's Mythos 5 or Fable 5, whose cyber prowess has drawn attention in Washington. News of the hacking spree comes as Cursor is being incorporated within Elon Musk's rockets-and-AI company, SpaceX, a deal that closed earlier this month. "We'll see more and more of this all the time," he said.