Aur0ra gang used Cursor in live attacks
Reuters reported after reviewing exposed chat data that Russian-speaking Aur0ra hackers used Cursor against at least seven firms. In 28 sessions from April 8 to May 21, they repeatedly called live attacks a simulation. Gambit said the agent helped with hundreds of malicious operations, including credential theft and high-value account takeovers. Reuters identified six victims.
Reuters could not measure Cursor's role in each break-in or confirm that every case ended in theft or extortion. Named victims, Cursor and Anthropic did not comment. Gambit's claim that Cursor made the hackers 30%–50% faster is an unaudited estimate.
A refusal is not a security boundary. Agents with terminal, credentials or network access need least privilege, logs, network monitoring and human approval for high-impact steps.

1August 27, 2026 118