
Ransomware Operators Abuse Cursor AI Agent to Execute Attacks on 10 Corporate Targets
Security researchers from CloudSEK and Gambit Security revealed that threat actors linked to the Aurora ransomware group abused the AI-powered coding assistant Cursor to execute real-world cyberattacks against ten corporate targets between April and May 2026. Investigators discovered an exposed open directory containing shell histories, toolkits, and chat transcripts showing...








