Hackers Put Cursor to Work, Plus 4 Tech Stories
There’s a difference between saying AI could make cybercrime faster and opening an attacker’s server and finding the AI chat logs sitting there. This morning we have the second one. Researchers examining infrastructure used by the Aurora ransomware operation found Cursor being used inside real victim networks to plan attacks, run commands, troubleshoot failures, and keep moving.
Aurora ransomware operators put Cursor to work inside victim networks
Reuters reports that Russian-speaking hackers used the Cursor coding agent while breaking into at least seven companies earlier this year. Gambit Security found the activity after discovering an Aurora server that had accidentally been left exposed to the internet, which is a fairly spectacular bit of operational security failure from people whose business is exploiting other people’s operational security.
The important part is what the recovered logs show. Gambit says it saw Cursor Agent used against ten target organizations between April 8 and May 21. In some cases the attacker gave the agent credentials or an existing route into the network, then asked it to do normal intrusion work: scan internal systems, enumerate Active Directory privileges, attempt NTLM relay attacks, abuse Active Directory Certificate Services, configure VPNs, and adapt when the first command didn’t work.
That distinction matters. Cursor did not spontaneously decide to become a ransomware operator, discover a company on its own, and launch an attack. A human criminal was directing it. But the human also didn’t have to type, research, and debug every step manually. Reuters quotes a Gambit researcher estimating that the agent may have made the attackers 30 to 50 percent faster.
The guardrails weren’t especially reassuring. Gambit and Reuters say Cursor refused some obviously malicious requests, but the operator repeatedly got around those refusals by restarting the conversation and insisting that the work was part of a legal simulation. In one recovered internal reasoning trace, the agent essentially accepted that claim and continued.
I think this is the more useful version of the “AI hackers are coming” story. They’re not coming. They’re here, and so far they look less like an autonomous cyberweapon than a criminal with a very fast assistant that can remember commands, generate scripts, explain unfamiliar techniques, and keep trying when something fails. That still changes the economics of an attack. A weakness that used to take an operator an hour to research may now take minutes.
For businesses, the defense is mostly unglamorous: phishing-resistant MFA where you can use it, least privilege, network segmentation, timely patching, good endpoint telemetry, and logs somebody will actually notice. AI doesn’t magically bypass all of that. It lets attackers work through mistakes and weak spots faster, which makes leaving the same weak spot around for six months a worse bet than it used to be.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
Avada and Fusion Builder need an immediate update
If you run WordPress with Avada, there’s a much simpler takeaway: update it.
Wordfence disclosed CVE-2026-18431, a 9.8-severity remote-code-execution flaw affecting Avada through version 7.16 when Fusion Builder through 3.16 is installed and active. Successful exploitation also requires certain administrator-authored content to be present, so this is not a claim that every Avada installation can be taken over with one request.
Where those conditions line up, though, the result is bad. The vulnerability is actually a chain of six separate authorization, trust, input-validation, and file-handling weaknesses. None is enough by itself. Put all six together and an unauthenticated attacker can write a PHP file to the server and execute it in the web server’s security context. In plain English: that can become a complete website compromise.
ThemeFusion released Avada 7.16.1 and Fusion Builder 3.16.1 on August 25. Update both components, not just whichever one WordPress happens to put in front of you first. If this is a production ecommerce or business site, take a current backup, apply the updates, clear caches, and verify the important stuff afterward — checkout, forms, logins, scheduled jobs, and anything custom.
There’s an interesting connection to the lead story: Wordfence says its own agentic security system found this six-step chain and produced a working proof of concept in about two hours. That’s a vendor describing its own research system, so I wouldn’t turn the stopwatch into a universal benchmark. But it does illustrate the other side of the same change. Defenders get faster tools, too. The race doesn’t become less serious just because both sides got a better engine.
WordPress security & maintenance
Keeping WordPress current is only part of keeping it healthy. Raymond Tec handles updates, backups, security monitoring, compatibility problems, access cleanup, and maintenance — plus the assorted weirdness that accumulates on a site over time.
A UK airport breach exposed data tied to 8.7 million customers
Manchester Airports Group says an unauthorized party accessed customer data connected with Manchester, London Stansted, and East Midlands airports. Reporting from the Financial Times and PA puts the affected population at about 8.7 million people, with the majority apparently exposed only through an email address collected during airport Wi-Fi signup.
MAG says the accessed information can also include phone numbers, vehicle registration numbers, and postcodes from parking, lounge, Fast Track, and Wi-Fi systems. The affected system did not hold bank or payment-card details. More importantly, this did not compromise aviation-security or airport-operating systems, and flights are operating normally.
For affected travelers, the practical risk is phishing. A message that knows you used Manchester Airport, has your email address, and perhaps knows enough about parking or another service to sound plausible has a head start over ordinary spam. MAG says it has contacted affected customers and will not unexpectedly ask for payment-card details, banking information, or passwords. If a travel-related message creates urgency, go to the airport or booking service directly rather than following the message’s link.
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
A judge says the Pentagon’s Anthropic blacklist was unlawful
A federal judge has blocked the Pentagon’s designation of Anthropic as a national-security supply-chain risk, and the ruling is much broader than a contract dispute over which chatbot the military gets to use.
Reuters reports that U.S. District Judge Rita F. Lin found the government’s actions amounted to unlawful retaliation under the First Amendment, denied Anthropic the process required by the Fifth Amendment, and violated the statute used to make the supply-chain designation. She called the designation “illegal and baseless.”
The fight started after Anthropic refused to remove restrictions on using Claude for domestic surveillance of Americans and fully autonomous weapons. Anthropic argued that the Pentagon retaliated against the company’s public AI-safety positions. The government argued that the dispute was about contractual restrictions: if the military couldn’t count on using Claude as it considered necessary during operations, that uncertainty itself created a supply-chain risk.
The court sided with Anthropic on the challenged designation. That does not mean the Pentagon is now required to use Claude, and it doesn’t give Anthropic control over military policy. The government can choose another provider or take other lawful procurement actions. What the ruling says is that the particular national-security mechanism used here couldn’t be turned into punishment for a company’s protected position without the legal basis and process the government was required to provide.
That boundary matters well beyond Anthropic. Frontier AI companies are increasingly being asked to decide where their products may be used, while governments increasingly see the same models as strategic infrastructure. Those interests are going to collide again. This ruling establishes one limit on how the U.S. government can respond when they do, although the broader legal fight is not necessarily over.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
Google’s “parasite SEO” penalty will work differently in Europe
Google is changing how one of its spam penalties works inside the European Economic Area beginning August 30, after discussions with the European Commission over the Digital Markets Act.
The site reputation policy targets third-party content placed on an established site primarily to borrow that site’s authority in search — the thing usually described as “parasite SEO.” Think a trusted publisher suddenly hosting a section of unrelated coupon, casino, loan, or affiliate content because the publisher’s domain can rank better than the third party could on its own.
Outside the EEA, a manual action under this policy will continue to directly affect the offending section’s Google results. Inside the EEA, Google says that direct effect won’t apply. Instead, Google may separate the third-party section in its systems so it ranks independently from the reputation of the host site. Site owners will still get the manual-action notice in Search Console, and eligible disputes can go through reconsideration and mediation.
So, no, Google did not just legalize parasite SEO in Europe. The policy still exists, the notice still exists, and the suspicious section may lose the very domain-level ranking advantage it was created to exploit. The practical advice for publishers doesn’t really change: if you host sponsored or partner content, make sure it exists because it serves your audience, not because somebody is renting your domain’s reputation.
That’s the common thread in this morning’s brief. AI is making real attackers faster. AI is helping defenders find uglier bugs faster. A familiar WordPress stack needs a patch. Millions of ordinary travelers have a new phishing risk. And two fights over who gets to control powerful platforms — the government or an AI vendor, Google or European regulators — are being turned into actual rules instead of abstract arguments. Technology gets interesting when it stops being theoretical. Today, very little of it is.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Reuters: Russian-speaking hackers used Cursor during real intrusions
- Gambit Security: Aurora ransomware and Cursor Agent analysis
- CloudSEK: The Aurora Files
- Wordfence: CVE-2026-18431 in Avada and Fusion Builder
- Manchester Airports Group: Data security incident update
- Financial Times: Manchester Airports Group breach
- Reuters: Judge blocks Pentagon’s Anthropic blacklisting
- Associated Press: Anthropic ruling and Pentagon dispute
- Google Search Central: Site reputation policy update
- Reuters: Google changes spam policy in the EEA
