Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

Thionne_WTZ · x · 2026-09-01

Threat actors associated with Aurora ransomware were observed using SpaceX's AI-powered coding assistant Cursor to plan and execute attacks. The agent handled exploitation tasks including network scanning, privilege checks, NTLM relay attempts, and certificate attacks against 10 targets. The findings are based on exposed infrastructure leaking months of activity.

Original post →

More from coding & agent

coding & agent channel →