i.s.c. Group published findings from CloudSEK and Gambit Security showing that threat actors associated with Aurora ransomware have been observed using SpaceX's AI-powered coding assistant Cursor to break into target networks.
Public source
Publisher name
Public post
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into…
Company
i.s.c. Group
i.s.c. Group - information security. delivered. since 1998. globally.
- Industry
- Security and Investigations
- Location
- Vienna, AT
- Company size
- 11–50 employees
About i.s.c. Group
information security consulting, founded in 1998 and having celebrated its 23rd year in 2021, is a consulting company focussing on all things information security. In over 500 projects since inception the company has assisted customers in achieving their information security goals and helped customers through trying and critical situations after a break-in or a cybercrime event. Having saved our customers from damages exceeding 25 million euros and with an unsurpassed consulting success rate the company is fit for whatever is next to come. Being the oldest and most experienced company focussing solely on strategic information security services in Austria, the DACH region, and probably Western Europe, and among the pioneers on the continent we are making the world a more secure place one ISMS or DPMS at a time. What's our USP? - We deliver. Always. Anywhere.
See moreLatest activity
Latest activity from i.s.c. Group
5 signals
Research & Knowledge
i.s.c. Group cybersecurity researchers unpacked JSCeal, a sophisticated compiled V8 JavaScript malware with credential harvesting, surveillance, and traffic-interception capabilities.
Products & Services
i.s.c. Group reported that every on-premises N-central build below 2026.3.1.14 needs Hotfix 4, with servers updated to Hotfix 3 a day earlier.
Research & Knowledge
i.s.c. Group analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common.
Discover more
Similar signals
Similar public activity from other companies.
Research & Knowledge
CloudSEK
CloudSEK disclosed exclusive details of Russian-speaking ransomware group aurora and how they used an AI coding assistant cursor to launch attacks targeting over 20 organisations.
Research & Knowledge
CISO community Nederland
CISO community Nederland published research from CloudSEK based on an exposed attacker server and chat history showing that Aurora ransomware operators used the agentic coding assistant Cursor during hands-on attacks against enterprise networks.
Research & Knowledge
Tuskira
Tuskira published a Threat Brief on August 31, 2026 detailing how Aurora ransomware operators used Cursor AI agent during intrusions.
Research & Knowledge
Kaseya
Kaseya published a recent report finding that the Aur0ra ransomware group using Cursor's AI agent during real attacks helped accelerate reconnaissance, credential theft, and exploitation, with researchers estimating the AI assistance may have made the attackers 30–50% faster.
Research & Knowledge
UltraViolet Cyber