Russian-speaking hackers used SpaceX's artificial intelligence (AI) coding assistant Cursor to lend technical support in cyberattacks targeting a Belgian chemical company and at least six other businesses earlier this year, according to data reviewed by Reuters and reports published by cybersecurity firms Gambit Security and CloudSek on Thursday (Aug 21).
Cursor is an AI programming tool developed by Anysphere, a US-based startup widely used internally by SpaceX, the space technology company owned by billionaire Elon Musk. The tool can automatically suggest and write source code, helping developers speed up their work.
According to researchers, the Russia-linked hacker group leveraged Cursor to craft exploit code, automate scanning processes, and identify vulnerabilities in the target companies' network systems. This highlights how commercial AI tools are increasingly being adopted by cybercriminal groups to enhance their attack capabilities.
Gambit Security and CloudSek said the attacks spanned various industries and countries, including a chemical company in Belgium. Cybersecurity experts warn that the use of AI in cyberattacks is becoming a worrying trend, requiring businesses to bolster their defensive measures.
Anysphere, the company behind Cursor, has not yet made an official comment on the matter. Meanwhile, SpaceX has also not responded to Reuters' requests for comment.
The incident raises concerns that commercial AI tools, designed for legitimate purposes, could be misused for criminal activities, and it also questions the responsibility of developers in preventing such abuse.