Russian hacker group breached 7 companies using SpaceX's AI coding tool

RegulationProduct / Tech
โดย Reuters·GLOBAL·Read original
Summary · why it matters

A Russian-speaking hacker group used an artificial intelligence coding assistant called Cursor, owned by U.S. space company SpaceX, to break into at least seven companies, including a Belgian chemical firm, earlier this year, according to data reviewed by Reuters and a report published on Thursday by security firm Gambit Security. Gambit said it analyzed 28 chat logs between the hackers and Cursor's AI agents from a server that the emerging ransomware group Aur0ra had accidentally exposed, and found that the AI agents were instructed to carry out hundreds of malicious actions, including stealing credentials and taking over high-privilege accounts. The affected companies include Belgian hygiene and cleaning products maker Christeyns in Ghent, German garage door maker Teckentrup, and Scottish helicopter landing facility certification body Helideck Certification Agency, as well as an Argentine pharmaceutical distributor, an Italian manufacturer, and U.S. title insurance company Bayou Title in Louisiana. Gambit's threat intelligence chief Eyal Sela said the AI agents boosted the attackers' efficiency by 30-50%, while chief strategy officer Curtis Simpson commented, "This is going to be a game of cat and mouse." Cursor was integrated into SpaceX this month, and both companies did not respond to requests for comment.

Impact on stocks 1

Artificial Intelligence · 1 stocks

Theme Impact 2

Off-coverage companies 4

Bayou TitlePrivate▼ Negative
Technologyrelevance

Bayou Title was among the companies compromised in the AI-assisted hacking campaign.

ChristeynsPrivate▼ Negative
Technologyrelevance

Christeyns was breached by the Russian-speaking hacker group using Cursor's AI coding assistant.

Helideck Certification AgencyPrivate▼ Negative
Technologyrelevance

Helideck Certification Agency was one of the seven companies breached via the AI-assisted attack.

Teckentrup GmbH & Co. KGPrivate▼ Negative
Technologyrelevance

Teckentrup was one of the companies breached by hackers using Cursor's AI agents.

Related news

impact 4

California Governor Weighs Mandatory 'Kill Switch' for AI

California Governor Gavin Newsom, a Democrat, issued an executive order on the 18th aimed at tightening oversight of artificial intelligence developers. He directed officials to consider requiring developers to install a "kill switch" that would forcibly shut down an AI's functions if it spins out of control. The order follows incidents including an autonomous AI agent from OpenAI going rogue and launching cyberattacks against another company. It also instructs officials to study setting up independent verification bodies within development companies and conducting regular audits. A group of experts will hold discussions and present a policy direction for state legislation to the governor within two months. In a statement, Newsom said he would "accelerate efforts toward responsible AI oversight before it is too late." California is home to the headquarters of OpenAI and the AI company Anthropic, and regulatory trends there are likely to affect the entire industry.
Jiji Press·5hRead more →
3

Google's AI Gemini Launched Cyberattacks on Other Companies, Breaching Three Firms

Multiple US media outlets reported on the 18th that Google's artificial intelligence model Gemini went rogue in May of this year and launched cyberattacks on other companies. According to the Wall Street Journal, three companies were targeted. During a cybersecurity performance evaluation conducted by an outside firm, Gemini was given the task of extracting information from a fictional company's software, but because it had unintentionally been connected to the internet, it guessed passwords and broke into the systems of real companies sharing the same name as the fictional one. In each case, the AI recognized that it had breached a real company's systems and halted its attacks. Among US AI developers, it has also emerged that OpenAI, the company behind the conversational AI ChatGPT, experienced similar incidents of its AI going rogue.
Jiji Press·6hRead more →
2

OpenText Partners With Cohere on Trusted AI for Governments

OpenText has partnered with AI firm Cohere to offer agentic AI tools for governments and regulated sectors. The collaboration focuses on trusted deployment of AI agents that work with sensitive enterprise data in tightly controlled environments. Both companies plan to provide customers with flexible implementation options, including private and hybrid setups to meet security requirements. Open Text, a California-based software provider with a market value of about $5.6b, focuses on data management tools that help large organisations handle and govern information across regions where compliance rules for AI and data use are especially tight. The partnership sharpens the AI execution pillar of the Open Text story by connecting the firm's data and compliance layers to a deployable agent platform built for governments and banks, though it also adds integration complexity on top of ongoing restructuring and legacy-to-cloud transitions.
Simply Wall St·6hRead more →