A Ransomware Crew Used Cursor As Staff
28AUG
Leaked logs show the Aur0ra ransomware crew running breaches through Cursor. 28 sessions, at least 7 victim companies. They told it the job was an authorized pentest.
No jailbreak involved. Just a plausible job description, which is how you use it too.
A researcher who read the transcripts puts their speed gain around 30-50 percent.
Guardrails assume honest operators. Nobody scoped abuse detection into agent surfaces.