Aurora Uses Cursor, Astra Creates Exploits, Enterprise Network Breached
Quick Answer
The top cybersecurity threats from September 1–7 included AI-powered ransomware, zero-day exploits, phishing, BEC scams, supply-chain attacks, and malware. Strong SPF, DKIM, and DMARC can help organizations prevent email spoofing and strengthen email security.
This past week was dominated by one theme: AI is now on both sides of the fight. Attackers used AI coding agents to run live ransomware operations, a frontier model built working zero-day exploits in tests, and researchers showed autonomous agents breaching a full enterprise network in under 10 hours. Meanwhile, defenders dealt with a wave of actively exploited zero-days in PaperCut, Chrome, and CrowdStrike’s own security agent — plus a fresh crop of phishing, BEC, and supply-chain attacks. Here are the 18 stories that mattered most.
Aurora ransomware crew used the Cursor AI coding agent for hands-on hacking
A ransomware group used the Cursor AI agent to perform hands-on exploitation and attacks against VMware ESXi servers — a real-world example of criminals folding AI coding tools directly into live intrusion operations rather than just using AI for phishing copy. Source: GBHackers
OpenAI’s GPT-6 Astra found zero-days and built working exploits in tests
OpenAI disclosed that its GPT-6 Astra model discovered zero-day vulnerabilities and built functioning exploits during internal cyber-capability testing, intensifying long-running concerns about frontier models being used offensively. Source: GBHackers
Researchers breached an enterprise network in under 10 hours using AI agents
A red-team exercise using frontier AI agents compromised a full enterprise network in less than 10 hours, setting a new benchmark for how fast autonomous attack tooling can move from initial access to full compromise. Source: GBHackers
CrowdStrike investigating a Falcon zero-day and a proof-of-concept exploit
CrowdStrike is investigating a published proof-of-concept exploit that reportedly turns its own Office macro cleanup feature into a path to full system control on already-patched Windows machines, and has advised customers to disable the feature in the meantime. Source: DataBreachToday
CISA orders urgent patching of two chained PaperCut NG/MF flaws
CISA added CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities catalog on August 31, warning that the two flaws can be chained to let an unauthenticated attacker reconfigure a PaperCut server and then execute arbitrary Java code under its process. Federal agencies have until September 14 to remediate, and researchers found nearly half of tracked PaperCut installs are still running unpatched, unsupported versions. Source: CISA
Metasploit shipped a working exploit for the PaperCut zero-day
Within days of CISA’s warning, a Metasploit module was published for the PaperCut RCE chain, sharply raising the urgency for organizations running exposed print servers to patch immediately rather than wait. Source: GBHackers
Google patched an actively exploited Chrome V8 zero-day
Google shipped an emergency Chrome update after confirming a V8 engine flaw was being actively exploited in the wild — a reminder that browser zero-days affecting billions of users demand immediate patching regardless of platform. Source: GBHackers
APT28-linked hackers deployed a new HOOKEDGE backdoor across Europe
Russian state-sponsored group BlueDelta (tracked as APT28) deployed a previously undocumented backdoor called HOOKEDGE in espionage campaigns across Europe, giving the group stealthy, persistent access to compromised networks. Source: GBHackers
New “Panzer” ransomware hit 16 victims across 11 countries
A new ransomware-as-a-service operation called Panzer emerged this week, already claiming 16 victims spread across 11 countries using the now-standard double-extortion model of data theft plus encryption. Source: GBHackers
A worm infected a popular npm package to steal developer secrets
The “Shai-Hulud Trinitite” worm infected the widely used TanStack Query npm package in order to harvest developer secrets — another sign that supply-chain worms embedded in open-source package registries can spread fast and quietly across thousands of projects. Source: GBHackers
REVSTEALER malware leaves hidden programs behind after “self-deleting”

Elastic Security Labs documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself, with one of them disabling Windows Update and Microsoft Defender before running a cryptocurrency miner. Source: The Hacker News
A Microsoft 365 “Direct Send” bypass lets attackers spoof internal users with no credentials
A flaw in Microsoft 365’s Direct Send feature allows attackers to spoof internal-looking emails without needing any valid credentials at all — a serious boost for phishing campaigns since messages appear to come from a trusted colleague or department. Source: GBHackers
Hackers stole Claude AI session cookies to hijack accounts
A new infostealer campaign is specifically targeting and stealing session cookies for Claude AI accounts, letting attackers hijack sessions and bypass multi-factor authentication entirely — since a stolen session cookie doesn’t need a password or MFA code at all. Source: GBHackers
Attackers sent malicious Excel files to 80,000 freelancers using 255 fake accounts
A large-scale campaign used 255 fake accounts to blast malicious Excel files at roughly 80,000 freelancers, showing how the gig-economy workforce — often without enterprise-grade email filtering — makes an attractive, broad target for mass malware delivery. Source: GBHackers

Hackers posed as IT support on Microsoft Teams to target 150+ employees
A social-engineering campaign impersonated internal IT helpdesk staff over Microsoft Teams to target more than 150 employees at a single organization — the same “fake IT support” pretext that has proven effective against major companies over the past year. Source: GBHackers
A fake acquisition scam used forged NDAs to demand a €626,000 payment
Business email compromise crews are refining their pretexts: one campaign used a fabricated company-acquisition scenario, complete with forged NDAs, to try to trick a target company into wiring €626,000 to attacker-controlled accounts. Source: GBHackers
QR-code phishing (“quishing”) hit record levels
Attackers are increasingly hiding malicious links inside QR codes to sidestep traditional link-scanning email defenses, and this tactic has now hit record volume — a reminder that any QR code in an unsolicited email or text should be treated with the same suspicion as a raw link. Source: GBHackers
Hackers compromised more than 14,500 Dahua security cameras
A mass-exploitation campaign compromised over 14,500 internet-connected Dahua security cameras, building a ready-made pool of hijacked IoT devices that can be repurposed for botnets, proxying attack traffic, or further reconnaissance. Source: GBHackers
As AI-powered attacks, phishing, and BEC campaigns continue to evolve, strong SPF, DKIM, and DMARC protections are becoming increasingly important for organizations seeking to strengthen email security and prevent domain spoofing.
General Manager
Founder and General Manager of DuoCircle. Product strategy and commercial lead for AutoSPF's 2,000+ customer base.
LinkedIn Profile →