Ransomware Operator Ran Cursor Agent Inside Ten Victim Networks
Gambit Security’s threat intelligence team has published a detailed account of the Aurora ransomware operation, including six weeks of session logs showing an operator driving SpaceX’s Cursor AI coding agent through hands-on exploitation inside ten target organizations between April 8, 2026 and May 21, 2026. Reuters, which first reported the findings on August 27, 2026,…