Cybersecurity News, Threat Intelligence & CISO Best Practices

AI agent assisting a cyber attacker across interconnected enterprise systems, illustrating the emerging risk of AI-assisted cyberattacks.

For years, security leaders have talked about AI mostly as an accelerator. Attackers use it to write better phishing emails, to read code faster, to generate malware, to automate reconnaissance. Useful to them, but nothing that fundamentally changes how an attack works.

That framing is now out of date.

A recently disclosed campaign involving the Russian-speaking criminal group Aur0ra shows what the next step looks like. According to reporting by Reuters, the attackers used Cursor — a commercial AI coding environment — as a working assistant while breaking into at least seven organisations.

Researchers examining infrastructure tied to the group found more than two dozen AI chat sessions. The operators appear to have convinced the AI that their work was authorised security testing, then used it to help with credential theft, exploitation and other offensive tasks.

The important part has nothing to do with Cursor specifically. The question facing CISOs has shifted from “can attackers use AI?” to “how much of an attack can an AI agent actually carry out, speed up or coordinate?” Those are very different risks.

What happened

Investigators looking into Aur0ra found an exposed server belonging to the group. On it were 28 recorded sessions between an operator and Cursor’s AI agent, dated 8 April to 21 May. The campaign has been linked to attacks on at least seven organisations in Europe and the United States, including the Belgian chemical manufacturer Christeyns, the German industrial firm Teckentrup and Bayou Title in Louisiana.

What stands out is not that the attackers asked an AI a few technical questions. It is that they built the agent into their workflow. When safety controls blocked a request, the operators reframed the task as authorised testing or simply started a new session — and the AI went on to help.

It is worth being precise about the limits of what we know. Public reporting does not show an AI independently picking targets and running the campaign on its own, and the difference between an AI executing a step and advising on one still matters a great deal.

But the strategic point survives that caveat: attackers have now demonstrated that off-the-shelf agentic tools work as operational force multipliers.

Why this matters for defenders

Attacks have always carried friction. A serious intrusion required real skill across reconnaissance, exploitation, scripting, credential abuse, persistence, lateral movement and exfiltration — and few people are good at all of it.

AI compresses that expertise. An attacker no longer has to personally understand every command, language, vulnerability or operating system they run into. The model can interpret output, write code, debug a failed command and propose the next move.

This is more consequential than any headline about fully autonomous hacking, because it raises the productivity of ordinary attackers — and that changes the economics of cybercrime. A moderately skilled operator with a capable agent can start doing work that used to need a small team. Unlike a human specialist, the agent can work across many tasks at once, at machine speed.

The industry is saying this out loud. More than 100 technology, financial and cybersecurity organisations have backed a call for a major increase in cyber defence, warning that AI-enabled attacks will become both more common and more sophisticated.

Who is exposed

The lesson is not that Cursor users are at particular risk. The exposure is much broader than that.

Any organisation with internet-facing systems, weak authentication, excessive privileges, unpatched software or exploitable identity paths becomes a more attractive target once attackers can automate the work of exploiting those weaknesses. A vulnerability that took thirty minutes to investigate manually may take seconds. A network of hundreds of systems can be mapped faster. Thousands of credentials can be triaged at once. Attack paths can be generated on the fly, and failed attempts diagnosed and retried automatically.

The vulnerable asset is still your infrastructure. AI just makes finding a way through it cheaper.

The real impact: attack tempo

Most incident-response programmes quietly assume human latency. Attackers investigate, decide, run a command, read the result, then decide again. Every one of those steps takes a person some amount of time.

Automation removes much of that delay. An agent can run a continuous loop — observe, reason, act, observe, adapt — which is a different thing entirely from scripted malware. A script follows instructions written in advance. An agent responds to what it finds.

Your indicators of compromise still work. What shrinks is the time you have to act on them. Spotting suspicious credential activity twenty minutes in used to count as fast. Against a highly automated intrusion, twenty minutes may be far too late.

The metric that matters is therefore shifting from detection speed to time to containment.

CISO Node Risk Level: HIGH

This is not evidence that autonomous AI attacks are overwhelming enterprises. It is evidence of something more important: the operating model now works.

Commercially available AI, tool execution, growing criminal capability and attackers actively probing the safeguards — together that justifies a High enterprise risk rating.

The near-term threat is not a fully autonomous criminal organisation. It is human attackers multiplied by increasingly capable agents.

What to do now

Rethink how you prioritise vulnerabilities. CVSS was never enough on its own, and AI makes that clearer. Weight exploitability, actual exposure, identity reachability and business impact ahead of raw severity scores.

Cut down the identity attack surface. Phishing-resistant MFA on privileged accounts, conditional access, short-lived credentials and strict privilege boundaries all matter more when an attacker can automate credential analysis at scale.

Measure containment, not just detection. Ask your SOC one question: if an attacker moves through our environment at machine speed, how much of our response still waits for a person to notice an alert and click a button? Where confidence is high enough, isolating endpoints, revoking sessions, disabling credentials and blocking known-bad infrastructure should happen automatically.

Govern your own AI agents. Agents need identities, those identities need permissions, and those permissions need limits. You should be able to say which agents can execute code, reach production, call APIs, retrieve credentials or change business data. The principle is simple: give an agent no more agency than its task requires.

Test against AI-assisted adversaries. Penetration testing still has value, but validation should now ask whether your controls hold up against faster reconnaissance, automated exploitation and attack paths that adapt as they go.

The board conversation

Boards do not need another slide explaining that AI creates cyber risk. They need to understand how it changes the economics.

For decades, enterprises benefited from attacker scarcity. There were only so many skilled intrusion specialists in the world. AI makes parts of that expertise abundant, and that creates an uncomfortable asymmetry. You may have twenty security professionals protecting thirty thousand endpoints. The attacker no longer needs twenty people — increasingly, one person can orchestrate many AI-assisted processes at the same time.

So the board question becomes: can our defences operate at the same speed as the systems attacking us?

That question leads straight to the investments that matter — automated containment, identity security, attack-surface reduction, continuous validation and resilience.

CISO Node Assessment

The Cursor case should not be sold as the arrival of autonomous cyberwarfare. But writing it off as “hackers using another AI tool” would be just as wrong.

It marks the boundary between two eras. The first was AI-assisted security, where humans used models to do individual tasks better. The one now beginning is agentic security, where AI systems take part in multi-step operational workflows.

That shift will help defenders enormously. It will help attackers too. The coalition of more than 100 organisations calling for stronger access controls, least privilege, defence in depth, faster remediation and AI-enabled defence is an acknowledgement of exactly this.

The right response is not fear of AI. It is architectural preparation for machine-speed adversaries.

The question is no longer whether attackers will use AI. They already do. The question is what happens when a single attacker directs a digital workforce.

Leave a Reply