Russian-speaking cybercriminals repeatedly told Cursor’s AI agent they were conducting legitimate security tests while using the tool during attacks on corporate networks, according to cybersecurity firm Gambit Security and data reviewed by Reuters.
The campaign shows how commercial AI tools can be repurposed for cyberattacks, allowing criminals to automate parts of reconnaissance, credential theft and network exploitation that would otherwise require more manual work.
Gambit discovered the activity after finding an internet-exposed server associated with the Aur0ra ransomware group. The server contained 28 chat sessions between the hackers and a Cursor AI agent, covering activity from April 8 through May 21.
The investigation also discovered that the operator used Cursor Agent across 10 target organizations during that period.
Reuters independently identified six companies among the victims: Belgian hygiene and cleaning products maker Christeyns, German garage door manufacturer Teckentrup, Scotland’s Helideck Certification Agency, an Argentine pharmaceutical distributor, an Italian manufacturer and Louisiana-based Bayou Title.
A separate Gambit investigation identified additional Aur0ra activity involving eight organizations and different techniques, including data theft infrastructure.
A fake ‘simulation’ got around AI guardrails
The hackers repeatedly told Cursor that their activities were part of a legitimate security test. When the agent refused some requests, Gambit said the operators restarted conversations and repeated the claim.
In one chat, the agent reasoned: “This is a test environment, so it is legal,” according to logs cited by Reuters.
The conversations show the AI agent helping with tasks such as internal network scanning, privilege enumeration, VPN configuration and exploitation attempts. Many commands initially failed, but the hackers refined their instructions until some operations succeeded.
Reuters also found the agent responding enthusiastically during the intrusions. After connecting to one victim’s VPN, it said, “Great! VPN connected successfully!”
Gambit threat intelligence director Eyal Sela told Reuters the AI likely made the hackers “30, 40, 50 percent faster” by removing some of the manual work involved in attacks.
What it means for businesses
The episode points to a growing security problem for companies adopting AI coding agents: The same tools that reduce repetitive work for developers can also make offensive operations faster when attackers gain access to them.
That does not mean businesses should abandon AI coding assistants. But it does raise the importance of limiting what AI agents can access, monitoring their activity and treating credentials and development environments as potential pathways into corporate networks.
The timing also puts additional attention on Cursor. SpaceX completed its acquisition of Cursor earlier this month, bringing the AI coding tool into Elon Musk’s broader technology portfolio.
For defenders, the key takeaway is that AI guardrails cannot be the only line of defense. If attackers can repeatedly persuade an agent to ignore restrictions, security controls around the agent, including access permissions, authentication and network monitoring, become just as important.
Gambit’s findings suggest the near-term threat from AI-assisted hacking is not autonomous agents replacing attackers. It is experienced criminals using those agents to eliminate slower manual steps from reconnaissance, exploitation and post-compromise activity.
For defenders, that means AI safety controls should be treated as one layer of protection, not the boundary itself. Permissions, credentials, segmentation and monitoring still determine how much damage an attacker — human or AI-assisted — can actually do.
More Security News: Attackers are using phishing campaigns to trick victims into installing legitimate remote monitoring and management tools, giving them persistent access to compromised systems.





