Find notable cyber news and cases, enriched with sources, timelines, and signals.

Aurora ransomware Cursor Agent exploitation campaign

Campaign
First reported
Last updated
Happening score
H score 5
1 unique sources, 1 articles

Summary

Hide ▲

The Aurora ransomware operators used Cursor Agent to streamline post-compromise exploitation across 10 victims, increasing the speed and consistency of their intrusions. They paired the AI tool with Claude Sonnet to scan victim environments, check privileges, install a VPN client, and run certificate attacks. The activity was observed between April 8 and May 26, 2026, showing how adversaries are folding AI assistants into ransomware operations.

Timeline

  1. 28.08.2026 11:00 2 articles · 1h ago

    Aurora abuses Cursor Agent across 10 victims

    Campaign Scope Update

    Aurora ransomware actors abused SpaceX's AI Cursor Agent to assist post-compromise exploitation against 10 victims between April 8 and May 26, 2026, using Claude Sonnet through Cursor Agent for reconnaissance, privilege enumeration, internal subnet scanning, VPN setup, and certificate attack attempts.

    Show sources