Find notable cyber news and cases, enriched with sources, timelines, and signals.

Aurora campaign expands across multiple victims

Campaign
First reported
Last updated
Happening score
H score 24
1 unique sources, 1 articles

Summary

Hide ▲

The Aurora (aka Aur0ra) ransomware operator used Cursor Agent with Claude Sonnet to assist hands-on exploitation against 10 targets between April 8 and May 21, 2026, extending a broader intrusion campaign across multiple victims. The activity increased the operator’s reach by combining AI-assisted tasking with direct exploitation work.

Related Happenings

Aurora ransomware Cursor Agent exploitation campaign

Campaign
H score24 First: 28.08.2026 11:00 Last: 28.08.2026 11:00 Sources 1

How related: Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security.

About this happening: Aurora ransomware operators used Cursor Agent and Claude Sonnet to support post-compromise exploitation against 10 victims between April 8 and May 26, 2026...

Ghostjacking AI hijacking attack using trusted logs and alerts

Technical Analysis
H score30 First: 10.08.2026 15:59 Last: 10.08.2026 15:59 Sources 1

About this happening: Researchers demonstrated Ghostjacking, an AI hijacking technique that turns trusted logs, alerts, and agent inputs into a command channel for agentic tools, creating risk...

Obsidian Security raises $85 million Series D

Commercial Activity
H score19 First: 04.08.2026 15:00 Last: 04.08.2026 15:00 Sources 1

About this happening: Obsidian Security raised $85 million in a Series D at a $1.1 billion valuation, adding capital to expand its agentic AI security business. The round lifts tota...

Microsoft Security launches Project Perception, MAI-Cyber-1-Flash, FORGE Lab, and EXTRA

Security Tool/Service
H score11 First: 28.07.2026 15:45 Last: 28.07.2026 15:45 Sources 1

About this happening: Microsoft Security launched Project Perception, an agentic security system that uses Red, Blue and Green agents to identify vulnerabilities, triage risk, and automate reme...

China-nexus agentic tools attack campaign targeting Japanese technology and East Asian cybersecurity organizations

Campaign
H score31 First: 11.05.2026 16:00 Last: 11.05.2026 16:00 Sources 1

About this happening: A China-nexus actor used agentic tools in a targeted attack against a Japanese technology firm and an East Asian cybersecurity platform, showing how AI-driven orch...

Timeline

  1. 31.08.2026 14:47 2 articles · 2h ago

    Aurora operators use Cursor Agent to plan intrusions against 10 targets

    Initial Disclosure

    CloudSEK and Gambit Security linked Aurora (aka Aur0ra) ransomware operators to Cursor/Cursor Agent-assisted hands-on exploitation against 10 targets between April 8 and May 21, 2026, while CloudSEK said exposed infrastructure showed months of activity against more than 20 organizations across nine countries between April and July 2026.

    Show sources