AI coding tools are now showing up in ransomware attack chains. According to a Reuters report citing Gambit Security, a Russian-speaking gang called Aur0ra used Cursor, the AI coding assistant owned by SpaceX, to break into at least seven companies.
What Happened
The breaches took place between April 8 and May 21, 2026. One confirmed target was a Belgian chemical company. Gambit Security attributed the intrusions to Aur0ra and identified Cursor as part of the attack toolchain.
The Operator Takeaway
This is the clearest public example yet of threat actors using mainstream AI dev tools to accelerate attacks. If your team uses Cursor or similar AI coding assistants, the tool itself is not the vulnerability, but the story is a reminder that AI lowers the skill floor for writing malicious code just as it lowers it for writing legitimate software.
Keep your incident response plans current. If you run any infrastructure that could be targeted, this is worth flagging to whoever handles your security posture.
