Aurora Ransomware Gang Abuses Cursor Agent in Attacks on 10 Organizations
Gambit Security reports that the Aurora ransomware gang has breached at least 10 organizations since around April 2026, abusing Cursor Agent (running Claude Sonnet) to assist intrusions against ESXi environments. The findings highlight the emerging weaponization of AI coding agents in cybercrime.
2026-08-27 ~ 2026-08-28 · 2 related posts
- Report: Aurora ransomware used Cursor Agent to help breach 10 organizations — cyb3rops · 2026-08-27
- Aurora Ransomware Abuses Cursor Agent for ESXi Attacks — cyb3rops · 2026-08-28