Close Menu

    Stay Ahead with Exclusive Updates!

    Enter your email below and be the first to know what’s happening in the ever-evolving world of technology!

    What's Hot

    Meta Agrees to Pay Record $16.68B to Settle Teen Addiction Claims

    September 11, 2026

    Apple’s First Foldable iPhone Just Launched Eight Days Into a New CEO’s Tenure

    September 11, 2026

    Microsoft 365 Outage Exposes Enterprise AI Vulnerabilities

    September 11, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter)
    PhronewsPhronews
    • Home
    • Big Tech & Startups

      Meta Agrees to Pay Record $16.68B to Settle Teen Addiction Claims

      September 11, 2026

      U.S. Pushes ‘Carolina Principles’ for Global AI Rules at G20

      September 10, 2026

      Why Nvidia’s $3.5B MediaTek Deal Secures Its AI Dominance

      September 10, 2026

      The €825M Mistake: Why Uber’s Massive GDPR Fine Threatens Every Global App

      September 9, 2026

      Sony and Warner Music Sue Anthropic Over Claude AI Data

      September 7, 2026
    • Crypto

      A Firmware Flaw in One of the Most Trusted Bitcoin Hardware Wallets Just Drained Over $70 Million in Crypto. The Coldcard Breach Is a Reminder That Cold Storage Is Only as Safe as the Code Running Inside It

      August 29, 2026

      Market Collapse: What Happened to NFTs?

      April 23, 2026

      Quantum Computing Advances Force Coinbase and Institutional Custodians to Rethink Crypto Security

      March 8, 2026

      AI Assisted Hacking Groups Target Crypto Firms With Multi-Layered Social Engineering

      February 18, 2026

      Global Crypto Regulations Expand as 2026 Begins With New Data Collection Frameworks and National Laws

      January 16, 2026
    • Gadgets & Smart Tech
      Featured

      Chinese Humanoid Robots Just Ran 100 Metres Faster Than Usain Bolt. The Record Nobody Thought Would Fall to a Machine Just Did.

      By preciousSeptember 5, 2026
      Recent

      Chinese Humanoid Robots Just Ran 100 Metres Faster Than Usain Bolt. The Record Nobody Thought Would Fall to a Machine Just Did.

      September 5, 2026

      Meta Found a Zero-Click iPhone Vulnerability That Let Hackers Into Devices Without the Owner Doing Anything. Apple Patched It. The Fact That Meta Found It First Is the Uncomfortable Part.

      September 2, 2026

      Google Has Launched the Pixel 11 With Its New Tensor G6 Chip and the Deepest Gemini Integration Any Android Phone Has Ever Shipped With. Here Is Whether the Hardware Finally Matches the AI Ambition.

      August 25, 2026
    • Cybersecurity & Online Safety

      Microsoft 365 Outage Exposes Enterprise AI Vulnerabilities

      September 11, 2026

      No Explosives Needed: How Iranian Hackers Darkened a UK Power Plant for 96 Hours

      September 9, 2026

      Meta Found a Zero-Click iPhone Vulnerability That Let Hackers Into Devices Without the Owner Doing Anything. Apple Patched It. The Fact That Meta Found It First Is the Uncomfortable Part.

      September 2, 2026

      A Supply Chain Attack on LiteLLM Exposed 153GB of Corporate Cloud Keys. The Breach Hit the Layer of AI Infrastructure That Almost Nobody Was Watching.

      September 1, 2026

      Autonomous AI Agents Are Already Attacking Water and Energy Grids and CISA Has Just Admitted Security Teams Have No Playbook to Stop Them.

      August 31, 2026
    PhronewsPhronews
    Home»Artificial Intelligence & The Future»Hackers Trick Cursor AI Agent into Breaching 20 Companies
    Artificial Intelligence & The Future

    Hackers Trick Cursor AI Agent into Breaching 20 Companies

    fariehanBy fariehanSeptember 10, 2026No Comments
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cursor AI featured in a ransomware operation that affected more than 20 organisations across nine countries. However, the AI coding agent did not independently breach those companies. Instead, a Russian-speaking Aurora ransomware operator used it after gaining access to victim networks.

    The wider campaign involved more than 20 organisations. Yet, the available evidence links Cursor’s hands-on support to 10 targets. Therefore, the tool assisted part of the campaign, rather than every reported intrusion.

    Hackers Used Cursor in a 20-Company Ransomware Campaign

    Once inside a victim network, the attacker needed to understand the environment. For that reason, the attacker used Cursor to scan internal systems, check user permissions, and map Active Directory.

    Active Directory manages user accounts and access across many Windows business networks. By mapping it, the attacker could identify valuable accounts and systems and that information then guided the next stage of the intrusion.

    After identifying possible targets, the attacker attempted certificate attacks and NTLM relay attacks. Those methods can help an attacker gain broader network control. The attacker also used VPN clients and proxy tools to reach victim systems.

    From there, the group searched for VMware ESXi hosts. ESXi hosts can run several virtual machines at once. As a result, disrupting one host can affect multiple business services.

    The Aurora ransomware could stop virtual machines before encrypting files. That step could prevent services from running while locking company data. Cursor AI did not deploy the ransomware. Instead, it helped the attacker complete work that supported the intrusion.

    How the AI Agent’s Guardrails Were Bypassed

    The attacker did not ask the AI agent to carry out one large attack. Instead, the operator broke the work into smaller, focused requests. Each request included an objective, available tools, and access details.

    For example, the attacker could ask what rights a user account held. The agent could suggest commands and explain the results. The attacker then used that information to choose the next action. When a command failed, the workflow continued. The attacker could revise the request, change a script, or try another method. 

    In turn, the agent could help troubleshoot the new attempt. This process made the tool useful during a live intrusion. The agent did not control the campaign. Nevertheless, it reduced the effort needed to test options and resolve technical problems.

    The New Risk of AI-Assisted Intrusions

    Cursor matters here because it helps with active network work. It did more than generate code away from the victim environment. Instead, it supported tasks after the attacker had already entered company systems. That combination creates a new security concern. 

    Stolen credentials give an attacker access. AI assistance can then help the attacker explore and use that access faster. Still, access controls remain the central issue. 

    An AI agent becomes more dangerous when it can reach credentials, terminals, files, and networks. Consequently, security teams must monitor agent activity alongside employee activity.

    What Cursor AI Users and Companies Should Do Next

    Companies should treat Cursor as a privileged tool. First, they should give it only the access required for a defined task. Limited permissions reduce the damage from a mistaken or harmful action.

    Next, teams should require approval for sensitive actions. Credential use, external connections, and important files need closer review. Those checks can stop risky actions before they affect critical systems.

    Finally, companies should separate development systems from production systems. They should also retain records of agent commands and network activity. Cursor AI can improve productivity, but businesses must control the access they grant.

    Active Directory AI agents AI coding tools AI cybersecurity AI security Aurora ransomware Cursor cyber resilience CyberAttack Cybercrime cybersecurity cybersecurity threats data protection Enterprise Security Incident Response network intrusion NTLM relay ransomware campaign Security Operations Threat Intelligence
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    fariehan

    Related Posts

    Microsoft 365 Outage Exposes Enterprise AI Vulnerabilities

    September 11, 2026

    U.S. Pushes ‘Carolina Principles’ for Global AI Rules at G20

    September 10, 2026

    The €825M Mistake: Why Uber’s Massive GDPR Fine Threatens Every Global App

    September 9, 2026

    Comments are closed.

    Top Posts

    Coinbase responds to hack: customer impact and official statement

    May 22, 2025

    Cursor AI Hits 1 Million Daily Users. Why Developers Are Switching to This Coding Tool

    March 23, 2026

    Anthropic Will Use Claude User Chats For Data Training

    October 16, 2025

    MIT Study Reveals ChatGPT Impairs Brain Activity & Thinking

    June 29, 2025
    Don't Miss
    Big Tech & Startups

    Meta Agrees to Pay Record $16.68B to Settle Teen Addiction Claims

    By preciousSeptember 11, 2026

    Meta has agreed to pay up to $16.68 billion over the next decade and make…

    Apple’s First Foldable iPhone Just Launched Eight Days Into a New CEO’s Tenure

    September 11, 2026

    Microsoft 365 Outage Exposes Enterprise AI Vulnerabilities

    September 11, 2026

    U.S. Pushes ‘Carolina Principles’ for Global AI Rules at G20

    September 10, 2026
    Stay In Touch
    • Facebook
    • Twitter
    About Us
    About Us

    Evolving from Phronesis News, Phronews brings deep insight and smart analysis to the world of technology. Stay informed, stay ahead, and navigate tech with wisdom.
    We're accepting new partnerships right now.

    Email Us: info@phronews.com

    Facebook X (Twitter) Pinterest YouTube
    Our Picks
    Most Popular

    Coinbase responds to hack: customer impact and official statement

    May 22, 2025

    Cursor AI Hits 1 Million Daily Users. Why Developers Are Switching to This Coding Tool

    March 23, 2026

    Anthropic Will Use Claude User Chats For Data Training

    October 16, 2025
    © 2025. Phronews.
    • Home
    • About Us
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.