Ransomware
Aurora ransomware operator used Cursor Agent in 10 intrusions and targeted ESXi hosts
Gambit Security says an Aurora ransomware operator used Cursor Agent inside 10 victim networks and paired it with tooling to find and encrypt VMware ESXi environments. According to Gambit Security, the operator used Cursor Agent, running Claude Sonnet, during hands-on activity across 10 organizations between April 8 and May