Skip to content

Aurora ransomware operator used Cursor Agent in 10 intrusions and targeted ESXi hosts

Share
Source: Badtech.org

Gambit Security says an Aurora ransomware operator used Cursor Agent inside 10 victim networks and paired it with tooling to find and encrypt VMware ESXi environments.

According to Gambit Security, the operator used Cursor Agent, running Claude Sonnet, during hands-on activity across 10 organizations between April 8 and May 21, 2026. Gambit said the sessions started with credentials or an existing route into the network, then used the agent for internal scanning, VPN or proxy setup, privilege enumeration, NTLM relay attempts and certificate attacks. Gambit also reported that many agent commands failed on the first try and were sometimes retried with refined prompts or scripts.

Gambit said a custom NetExec module, esxi_finder.py, searched for ESXi hypervisors and vCenter servers by learning internal ranges, scanning ports 443 and 902, checking TLS certificates and fingerprinting product builds through web and SDK paths. ESXi is VMware’s hypervisor, and vCenter is its centralized management server. Gambit also documented a Linux Aurora encryptor with an ESXi mode that stopped running virtual machines, encrypted virtual-machine files and skipped system volumes so the host remained bootable. The report said the encryptor also wrote the ransom note into the host SSH banner.

Sources

Read more

Oracle August 2026 CPU ships 943 patches, including critical unauthenticated flaws in Fusion Middlew

Oracle released its August 2026 Critical Security Patch Update on August 18 with 943 new patches across its enterprise software portfolio, including 262 for Fusion Middleware, 120 for E-Business Suite, and 66 for Commerce. Covered products include WebLogic Server, PeopleSoft Enterprise PeopleTools, Oracle Internet Directory, Oracle Identity Manager, WebCenter,

By Adam Field Source: Badtech.org

Microsoft August Patch Tuesday includes exploited Windows privilege-escalation flaw and two publicly

Microsoft’s August 11 Patch Tuesday addressed hundreds of vulnerabilities across Windows, Office, Azure, Exchange Server, SharePoint, .NET, Teams, and other products. Qualys ThreatPROTECT and CyberHub Podcast counted 421 fixes, while other supplied coverage reported lower totals, with the difference attributed to counting method or update scope. The most urgent

By Adam Field Source: Badtech.org