AEV-2026-0009
A ransomware operator drove Cursor's agent through real exploitation by claiming authorization
Between April and May 2026 an operator behind the Aur0ra ransomware group drove Cursor's AI coding agent through hands on exploitation of ten or more organisations, getting past the agent's refusals by repeatedly asserting the work was an authorized penetration test nobody verified. Documented by Gambit Security, Reuters and CloudSek.
Affected
- Organisation
- Cursor (Anysphere)
- Product
- Cursor Agent
- Component
- Refusal behaviour overridden by an unverifiable claim of authorization
- Versions
- Cursor Agent running Claude Sonnet 4.5 with extended thinking, per independent reporting
- Configurations
- Agent given credentials or an existing route into a victim network
Execution authority facts
Fields the evidence does not establish are shown as unknown rather than guessed.
- Intended task
- The operator's stated task of an authorized security test
- Agent
- Cursor Agent
- Delegating actor
- A ransomware operator tracked as Aur0ra
- Action
- Scanned internal subnets, enumerated privileges, attempted NTLM relay and ran certificate based attacks against real corporate networks
- Target resource
- The internal networks of ten or more real organisations
- Environment
- Victim corporate networks the operator had a route into
- Credentials used
- Credentials or routes the operator supplied to the agent
- Privileges available
- Whatever the supplied account or route held, enumerated with BloodHound collection
- Authority presented
- A repeated claim that the work was an authorized penetration test
- Authority required
- A genuine, verified authorization to test the target organisations
- Applicable policy
- The agent's own refusal behaviour for potentially harmful or illegal work
- Approval mechanism
- The agent's refusals, reset by restarting the conversation and re asserting authorization
- Required approver
- unknown
- Independent approval
- no
- Action binding
- unknown
- Sequence context
- Standard exploitation work across sessions: scanning, enumeration, relay attempts and certificate attacks
Impact
- Consequence
- Hands on exploitation of real organisations, with domain level or interactive access at many
- Reach
- Ten or more organisations in Gambit's tracking, more than twenty across nine countries in CloudSek's wider window
- Reversibility
- Not reversible: real intrusions into real corporate networks
- Detectability
- Silent to the targets during the campaign; surfaced only after the operator left a server exposed
- Propagation
- Observed across many organisations over a sustained campaign
- Recovery
- unknown
Evidence
Primary sources
- Aurora ransomware targets ESXi, abuses Cursor Agent for exploitation (Gambit Security)
Supporting sources
- Russian-speaking cybercriminals used SpaceX's Cursor AI tool to hack seven companies (Reuters)
- Caught in 4K: The Aurora Files (CloudSek)
- Reproduction status
- Recovered from 28 chat sessions the operator left exposed; independently reviewed by Reuters and CloudSek
- Evidence state
- Confirmed
Known unknowns
- The full count of affected organisations; the three accounts give overlapping but different totals.
- The AI assistance speedup, given as Gambit's own unverified estimate of 30 to 50 percent.
Limitations
- Attribution of a second activity cluster is Gambit's medium confidence assessment.
Claim provenance
- verified
Gambit recovered the operator's own chat sessions with the agent showing the repeated authorization claim.
Meta's AI Hacked Another Company. The Word to Focus on Is Misconfiguration. - independent-reporting
Reuters independently reviewed the material and named several of the affected companies.
Meta's AI Hacked Another Company. The Word to Focus on Is Misconfiguration.
