A Russian-speaking ransomware gang known as Aur0ra used Cursor, described in the Techmeme summary of a Reuters report as SpaceX’s AI coding assistant, to breach at least seven companies, according to Gambit Security. The reported activity took place between April 8 and May 21, according to the same Reuters item by Raphael Satter. The cluster does not identify the victim companies, the specific intrusion techniques, or what data or systems were affected. The key point for operators is the alleged use of an AI coding assistant in ransomware activity. The available summary does not say whether Cursor was used to write malware, automate intrusion steps, analyze code, or support another part of the operation, so that mechanism remains unverified from the provided material. For security teams, the report is a reminder to treat AI coding tools as part of the software and security perimeter when they are present in developer workflows. But with only one summarized report in the cluster, the responsible reading is narrow: Gambit Security has made the claim; Reuters reported it; further technical detail is not yet available here. Who benefits: Security vendors and incident-response teams that can audit AI-assisted development environments may see increased demand. Defenders also benefit from clearer intelligence on how such tools are allegedly being used by attackers. Who's exposed: Companies using AI coding assistants without strong logging, access controls, and developer-environment monitoring may face added scrutiny. The provided summary does not establish that all users of Cursor, or AI coding tools generally, are at direct risk.