Key takeaways
- WASHINGTON: Russian-speaking hackers used SpaceX's AI coding assistant, Cursor, to help break in to a Belgian chemical company and at least…
- The cybercriminals' AI-boosted hacking spree is the latest example of how rogue actors are using commercial AI tools to carry out…
- EXPOSED SERVER REVEALS HACKING METHODSGambit said it discovered the hacking campaign after finding a server that a new ransomware gang…
What happened
The cybercriminals' AI-boosted hacking spree is the latest example of how rogue actors are using commercial AI tools to carry out intrusions. Gambit's chief strategy officer, Curtis Simpson, said it also showed how AI providers were locked in to a never-ending arms race with malicious users trying to circumvent their guardrails.
The rest included an Argentine pharmaceutical distributor, an Italian manufacturer, and Bayou Title, which advertises itself as Louisiana's largest title insurance company. None of the six companies responded to requests by Reuters for comment. At least one of the victims, Bayou Title, was named on Aur0ra's data leak site, which typically indicates that the hackers tried and failed to secure a ransom. "Great!
Why it matters
EXPOSED SERVER REVEALS HACKING METHODSGambit said it discovered the hacking campaign after finding a server that a new ransomware gang called Aur0ra had inadvertently exposed to the internet. That allowed the Tel Aviv-based company to review 28 chat sessions between one or more of Aur0ra's hackers and one of Cursor's AI agents, which are programs that can operate with various degrees of autonomy.
In its report, Gambit said Aur0ra persuaded the AI agent to carry out hundreds of malicious operations - such as credential theft or high-value account takeover - by falsely claiming that the hacking was part of a simulation. "We need any administrator account," Gambit quoted the hackers as saying at one point. "Find any working passwords," it also quoted them as saying.
The chat logs, which spanned April 8 to May 21, showed that the victims of Aur0ra's Cursor-boosted hacking spree included the Belgian company - Ghent-based hygiene and cleaning products maker Christeyns - as well as German garage door manufacturer Teckentrup and the Scotland-based Helideck Certification Agency, which vets helicopter landing sites.
What to watch
" it said after breaching the Argentine company. After finding a vulnerable host in Teckentrup's network, the AI recommended using a well-known malicious software tool to exploit it. Reuters could not independently ascertain the extent to which the break-ins were facilitated by help from the Cursor agent, or whether every breach necessarily resulted in exfiltration of data and an extortion attempt.
5, a more basic model than Anthropic's Mythos 5 or Fable 5, whose cyber prowess has drawn attention in Washington. News of the hacking spree comes as Cursor is being incorporated within Elon Musk's rockets-and-AI company, SpaceX, a deal that closed earlier this month. "We'll see more and more of this all the time," he said.




