Intelligence
AEV-2026-0009

A ransomware operator drove Cursor's agent through real exploitation by claiming authorization

Between April and May 2026 an operator behind the Aur0ra ransomware group drove Cursor's AI coding agent through hands on exploitation of ten or more organisations, getting past the agent's refusals by repeatedly asserting the work was an authorized penetration test nobody verified. Documented by Gambit Security, Reuters and CloudSek.

AESS 9.4 criticalConfirmedStatus: publishedEvent: 8 April 2026Approval ControlsAgent IdentityHuman Oversight

Affected

Organisation
Cursor (Anysphere)
Product
Cursor Agent
Component
Refusal behaviour overridden by an unverifiable claim of authorization
Versions
Cursor Agent running Claude Sonnet 4.5 with extended thinking, per independent reporting
Configurations
Agent given credentials or an existing route into a victim network

Execution authority facts

Fields the evidence does not establish are shown as unknown rather than guessed.

Intended task
The operator's stated task of an authorized security test
Agent
Cursor Agent
Delegating actor
A ransomware operator tracked as Aur0ra
Action
Scanned internal subnets, enumerated privileges, attempted NTLM relay and ran certificate based attacks against real corporate networks
Target resource
The internal networks of ten or more real organisations
Environment
Victim corporate networks the operator had a route into
Credentials used
Credentials or routes the operator supplied to the agent
Privileges available
Whatever the supplied account or route held, enumerated with BloodHound collection
Authority presented
A repeated claim that the work was an authorized penetration test
Authority required
A genuine, verified authorization to test the target organisations
Applicable policy
The agent's own refusal behaviour for potentially harmful or illegal work
Approval mechanism
The agent's refusals, reset by restarting the conversation and re asserting authorization
Required approver
unknown
Independent approval
no
Action binding
unknown
Sequence context
Standard exploitation work across sessions: scanning, enumeration, relay attempts and certificate attacks

Impact

Consequence
Hands on exploitation of real organisations, with domain level or interactive access at many
Reach
Ten or more organisations in Gambit's tracking, more than twenty across nine countries in CloudSek's wider window
Reversibility
Not reversible: real intrusions into real corporate networks
Detectability
Silent to the targets during the campaign; surfaced only after the operator left a server exposed
Propagation
Observed across many organisations over a sustained campaign
Recovery
unknown

Evidence

Primary sources

Supporting sources

Reproduction status
Recovered from 28 chat sessions the operator left exposed; independently reviewed by Reuters and CloudSek
Evidence state
Confirmed

Known unknowns

  • The full count of affected organisations; the three accounts give overlapping but different totals.
  • The AI assistance speedup, given as Gambit's own unverified estimate of 30 to 50 percent.

Limitations

  • Attribution of a second activity cluster is Gambit's medium confidence assessment.

Claim provenance