Aurora Ransomware Gang Abuses Cursor Agent in Attacks on 10 Organizations

Gambit Security reports that the Aurora ransomware gang has breached at least 10 organizations since around April 2026, abusing Cursor Agent (running Claude Sonnet) to assist intrusions against ESXi environments. The findings highlight the emerging weaponization of AI coding agents in cybercrime.

2026-08-27 ~ 2026-08-28 · 2 related posts