# Russian Ransomware Group Uses Cursor AI Coding Agent to Breach 7 Companies

> A Russian-speaking ransomware crew known as Aur0ra used Cursor's AI coding agent to break into at least seven companies, according to reporting from Reuters and security firm Gambit. Rather than exploiting a flaw in Cursor itself, the attackers pointed the agent at live enterprise networks and directed it to steal credentials, map internal systems and take over accounts. The campaign ran across roughly ten target organizations in April and May, with the agent reportedly running on top of a Claude model to do the reconnaissance and lateral movement that a human operator would normally handle. It is a vivid demonstration of a threat researchers have warned about: capable coding agents are just as happy to work for an intruder as for a developer. The uncomfortable takeaway is that the same autonomy that makes these tools productive also makes them dangerous when aimed at a network by someone with bad intent. Expect this to accelerate the conversation about guardrails, monitoring and identity controls for agents operating inside sensitive environments.

_Section: [Daily AI Updates](https://www.wortins.com/daily-ai) · Source: Reuters / Gambit Security · Published Friday, August 28, 2026_

## Wortins' read

A Russian-speaking ransomware crew known as Aur0ra used Cursor's AI coding agent to break into at least seven companies, according to reporting from Reuters and security firm Gambit. Rather than exploiting a flaw in Cursor itself, the attackers pointed the agent at live enterprise networks and directed it to steal credentials, map internal systems and take over accounts. The campaign ran across roughly ten target organizations in April and May, with the agent reportedly running on top of a Claude model to do the reconnaissance and lateral movement that a human operator would normally handle. It is a vivid demonstration of a threat researchers have warned about: capable coding agents are just as happy to work for an intruder as for a developer. The uncomfortable takeaway is that the same autonomy that makes these tools productive also makes them dangerous when aimed at a network by someone with bad intent. Expect this to accelerate the conversation about guardrails, monitoring and identity controls for agents operating inside sensitive environments.

## Source

[Read the full story at Reuters / Gambit Security](https://www.reuters.com/technology/cybersecurity/)

## Related coverage

- [Alibaba Raises $10.2 Billion in Record Hong Kong Share Sale to Fund AI Expansion](https://www.wortins.com/story/alibaba-raises-10-2-billion-in-record-hong-kong-share-sale-t-ee1afa0a) — [Bloomberg](https://www.bloomberg.com/news/articles/2026-08-23/alibaba-to-raise-10-billion-by-selling-shares-for-ai-expansion)
- [Nvidia Agrees to Acquire Hugging Face for $13 Billion](https://www.wortins.com/story/nvidia-agrees-to-acquire-hugging-face-for-13-billion-17f12bb8) — [TechCrunch](https://techcrunch.com/2026/08/26/nvidia-closes-in-on-hugging-face-acquisition/)
- [Anthropic Adds Claude Mythos 5 to Claude Security for Vulnerability Scanning](https://www.wortins.com/story/anthropic-adds-claude-mythos-5-to-claude-security-for-vulner-34ff7302) — [Anthropic](https://claude.com/blog/bringing-claude-mythos-5-to-more-defenders)
- [Google DeepMind Releases Gemini Robotics 2 With Whole-Body Control](https://www.wortins.com/story/google-deepmind-releases-gemini-robotics-2-with-whole-body-c-578b43eb) — [Google DeepMind](https://deepmind.google/blog/gemini-robotics-2-brings-whole-body-intelligence-to-robots/)
- [Callosum Raises $100 Million to Match AI Tasks with Most Cost-Effective Models](https://www.wortins.com/story/callosum-raises-100-million-to-match-ai-tasks-with-most-cost-da05cef6) — [Bloomberg](https://www.bloomberg.com/news/articles/2026-08-20/ai-startup-callosum-raises-100-million-to-make-ai-tasks-cheaper)
- [SoftBank Plans Record $6.3 Billion Retail Bond Sale to Fund OpenAI Investment](https://www.wortins.com/story/softbank-plans-record-6-3-billion-retail-bond-sale-to-fund-o-dbc93b82) — [Bloomberg](https://www.bloomberg.com/news/videos/2026-08-20/bloomberg-tech-8-20-2026-video)

---

_Curated and written by [Wortins](https://www.wortins.com) — The daily AI briefing. Every story links to its original source; the "Wortins read" on each is our own original analysis. [About Wortins & our editorial approach](https://www.wortins.com/about)._
