Aurora campaign expands across multiple victims
Campaign
Summary
Hide ▲
Show ▼
The Aurora (aka Aur0ra) ransomware operator used Cursor Agent with Claude Sonnet to assist hands-on exploitation against 10 targets between April 8 and May 21, 2026, extending a broader intrusion campaign across multiple victims. The activity increased the operator’s reach by combining AI-assisted tasking with direct exploitation work.
Related Happenings
Aurora ransomware Cursor Agent exploitation campaign
Campaign
H score24
First: 28.08.2026 11:00
Last: 28.08.2026 11:00
Sources 1
How related:
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security.
About this happening:
Aurora ransomware operators used Cursor Agent and Claude Sonnet to support post-compromise exploitation against 10 victims between April 8 and May 26, 2026...
Aurora ransomware Cursor Agent exploitation campaign
CampaignHow related: Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security.
About this happening: Aurora ransomware operators used Cursor Agent and Claude Sonnet to support post-compromise exploitation against 10 victims between April 8 and May 26, 2026...
Ghostjacking AI hijacking attack using trusted logs and alerts
Technical Analysis
H score30
First: 10.08.2026 15:59
Last: 10.08.2026 15:59
Sources 1
About this happening:
Researchers demonstrated Ghostjacking, an AI hijacking technique that turns trusted logs, alerts, and agent inputs into a command channel for agentic tools, creating risk...
Ghostjacking AI hijacking attack using trusted logs and alerts
Technical AnalysisAbout this happening: Researchers demonstrated Ghostjacking, an AI hijacking technique that turns trusted logs, alerts, and agent inputs into a command channel for agentic tools, creating risk...
Obsidian Security raises $85 million Series D
Commercial Activity
H score19
First: 04.08.2026 15:00
Last: 04.08.2026 15:00
Sources 1
About this happening:
Obsidian Security raised $85 million in a Series D at a $1.1 billion valuation, adding capital to expand its agentic AI security business. The round lifts tota...
Obsidian Security raises $85 million Series D
Commercial ActivityAbout this happening: Obsidian Security raised $85 million in a Series D at a $1.1 billion valuation, adding capital to expand its agentic AI security business. The round lifts tota...
Microsoft Security launches Project Perception, MAI-Cyber-1-Flash, FORGE Lab, and EXTRA
Security Tool/Service
H score11
First: 28.07.2026 15:45
Last: 28.07.2026 15:45
Sources 1
About this happening:
Microsoft Security launched Project Perception, an agentic security system that uses Red, Blue and Green agents to identify vulnerabilities, triage risk, and automate reme...
Microsoft Security launches Project Perception, MAI-Cyber-1-Flash, FORGE Lab, and EXTRA
Security Tool/ServiceAbout this happening: Microsoft Security launched Project Perception, an agentic security system that uses Red, Blue and Green agents to identify vulnerabilities, triage risk, and automate reme...
China-nexus agentic tools attack campaign targeting Japanese technology and East Asian cybersecurity organizations
Campaign
H score31
First: 11.05.2026 16:00
Last: 11.05.2026 16:00
Sources 1
About this happening:
A China-nexus actor used agentic tools in a targeted attack against a Japanese technology firm and an East Asian cybersecurity platform, showing how AI-driven orch...
China-nexus agentic tools attack campaign targeting Japanese technology and East Asian cybersecurity organizations
CampaignAbout this happening: A China-nexus actor used agentic tools in a targeted attack against a Japanese technology firm and an East Asian cybersecurity platform, showing how AI-driven orch...
Timeline
-
31.08.2026 14:47 2 articles · 2h ago
Aurora operators use Cursor Agent to plan intrusions against 10 targets
Initial DisclosureCloudSEK and Gambit Security linked Aurora (aka Aur0ra) ransomware operators to Cursor/Cursor Agent-assisted hands-on exploitation against 10 targets between April 8 and May 21, 2026, while CloudSEK said exposed infrastructure showed months of activity against more than 20 organizations across nine countries between April and July 2026.
Show sources
- Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets — thehackernews.com — 31.08.2026 14:47
- Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets — thehackernews.com — 31.08.2026 14:47