---
title: "Aurora Uses Cursor, Astra Creates Exploits, Enterprise Network Breached   | AutoSPF"
description: "Explore the top cybersecurity news from September 1–7, covering AI-powered attacks, zero-days, ransomware, phishing, BEC, and email security threats."
image: "https://autospf.com/og/blog/aurora-uses-cursor-astra-creates-exploits-enterprise-network-breached.png"
canonical: "https://autospf.com/blog/aurora-uses-cursor-astra-creates-exploits-enterprise-network-breached/"
---

Quick Answer

The top cybersecurity threats from September 1–7 included AI-powered ransomware, zero-day exploits, phishing, BEC scams, supply-chain attacks, and malware. Strong SPF, DKIM, and DMARC can help organizations prevent email spoofing and strengthen email security.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fautospf.com%2Fblog%2Faurora-uses-cursor-astra-creates-exploits-enterprise-network-breached%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Aurora%20Uses%20Cursor%2C%20Astra%20Creates%20Exploits%2C%20Enterprise%20Network%20Breached%20%20&url=https%3A%2F%2Fautospf.com%2Fblog%2Faurora-uses-cursor-astra-creates-exploits-enterprise-network-breached%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fautospf.com%2Fblog%2Faurora-uses-cursor-astra-creates-exploits-enterprise-network-breached%2F "Share on Facebook") [ ](https://reddit.com/submit?url=https%3A%2F%2Fautospf.com%2Fblog%2Faurora-uses-cursor-astra-creates-exploits-enterprise-network-breached%2F&title=Aurora%20Uses%20Cursor%2C%20Astra%20Creates%20Exploits%2C%20Enterprise%20Network%20Breached%20%20 "Share on Reddit") [ ](mailto:?subject=Aurora%20Uses%20Cursor%2C%20Astra%20Creates%20Exploits%2C%20Enterprise%20Network%20Breached%20%20&body=Check out this article: https%3A%2F%2Fautospf.com%2Fblog%2Faurora-uses-cursor-astra-creates-exploits-enterprise-network-breached%2F "Share via Email") 

![AI Cybersecurity Threat Report](https://media.mailhop.org/autospf/spf-lookup-6402-1788959755029.jpg) 

This past week was dominated by one theme: AI is now on both sides of the fight. Attackers used AI coding agents to run live ransomware operations, a frontier model built working zero-day exploits in tests, and researchers showed autonomous agents breaching a full enterprise network in under 10 hours. Meanwhile, defenders dealt with a wave of actively exploited zero-days in PaperCut, Chrome, and CrowdStrike’s own **security agent** — plus a fresh crop of phishing, [BEC](https://www.cybersecuritydive.com/news/fbi-internet-crime-bec-scams-investment-fraud-losses/746181/), and supply-chain attacks. _Here are the 18 stories that mattered most_.

## Aurora ransomware crew used the Cursor AI coding agent for hands-on hacking

A ransomware group used the [Cursor AI agent](https://tech-insider.org/cursor-ai-hack-agentic-ai-governance-rules-2026/) to perform hands-on exploitation and attacks against **VMware ESXi servers** — a real-world example of criminals folding AI coding tools directly into live intrusion operations rather than just using AI for phishing copy. [Source: GBHackers](https://gbhackers.com/cursor-ai-powered-ransomware/)

## OpenAI’s GPT-6 Astra found zero-days and built working exploits in tests

OpenAI disclosed that its [GPT-6 Astra](https://decrypt.co/377341/openai-releases-gpt-6-astra-agi) model discovered zero-day vulnerabilities and built functioning exploits during internal **cyber-capability testing**, intensifying long-running concerns about frontier models being used offensively. [Source: GBHackers](https://gbhackers.com/openai-gpt-6-astra-discovers-zero-day-flaws/)

## Researchers breached an enterprise network in under 10 hours using AI agents

![Spf Record Checker 9711](https://media.mailhop.org/autospf/spf-record-checker-9711-1788954824606.jpg)A red-team exercise using frontier [AI agents](https://cybermagazine.com/news/unit-42-how-ai-agents-breached-a-network-in-10-hours) compromised a full enterprise network in less than 10 hours, setting a new benchmark for how fast autonomous attack tooling can move from initial access to full compromise. [Source: GBHackers](https://gbhackers.com/hackers-use-frontier-ai-agents/)

## CrowdStrike investigating a Falcon zero-day and a proof-of-concept exploit

[CrowdStrike is investigating](https://www.databreachtoday.com/crowdstrike-probes-falcon-zero-day-exploit-code-a-32753) a published proof-of-concept exploit that reportedly turns its own Office macro cleanup feature into a path to full system control on already-patched Windows machines, and has advised customers to disable the feature in the meantime. [Source: DataBreachToday](https://www.databreachtoday.com/)

## CISA orders urgent patching of two chained PaperCut NG/MF flaws

CISA added **CVE-2026-81578 and CVE-2026-82078** to its Known [Exploited Vulnerabilities catalog](https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog) on August 31, warning that the two flaws can be chained to let an unauthenticated attacker reconfigure a PaperCut server and then execute arbitrary Java code under its process. _Federal agencies have until September 14 to remediate, and researchers found nearly half of tracked PaperCut installs are still running unpatched, unsupported versions._ [Source: CISA](https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog)

## Metasploit shipped a working exploit for the PaperCut zero-day

Within days of **CISA’s warning**, a Metasploit module was published for the [PaperCut RCE chain](https://www.bankinfosecurity.com/attackers-actively-exploit-flaws-in-papercut-ngmf-a-32696), sharply raising the urgency for organizations running exposed print servers to patch immediately rather than wait. [Source: GBHackers](https://gbhackers.com/metasploit-adds-exploit-for-papercut-mf-ng-zero-day/)

## Google patched an actively exploited Chrome V8 zero-day

![Spf Flattening 5107](https://media.mailhop.org/autospf/spf-flattening-5107-1788955216416.jpg)Google shipped an emergency Chrome update after confirming a [V8 engine flaw](https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html) was being actively exploited in the wild — a reminder that browser zero-days affecting billions of users demand immediate patching regardless of platform. [Source: GBHackers](https://gbhackers.com/google-chrome-v8-flaw/)

## APT28-linked hackers deployed a new HOOKEDGE backdoor across Europe

[Russian state-sponsored group BlueDelta](https://www.arabnews.com/world/germany-intelligence-agency-warns-of-russian-apt28-cyber-spying-2639156) (tracked as APT28) deployed a previously undocumented backdoor called **HOOKEDGE** in espionage campaigns across Europe, giving the group stealthy, persistent access to compromised networks. [Source: GBHackers](https://gbhackers.com/russian-apt28-linked-hackers-deploy-hookedge-backdoor/)

## New “Panzer” ransomware hit 16 victims across 11 countries

A new [ransomware-as-a-service operation called Panzer](https://cybersecuritynews.com/panzer-ransomware-targets/) emerged this week, already claiming 16 victims spread across **11 countries** using the now-standard double-extortion model of data theft plus encryption. [Source: GBHackers](https://gbhackers.com/new-panzer-ransomware-hits-16-victim/)

## A worm infected a popular npm package to steal developer secrets

The “Shai-Hulud Trinitite” worm infected the widely used [TanStack Query npm package](https://cybersecuritynews.com/shai-hulud-npm-worm/amp/) in order to harvest developer secrets — _another sign that supply-chain worms embedded in open-source package registries can spread fast and quietly across thousands of projects._ [Source: GBHackers](https://gbhackers.com/shai-hulud-trinitite-worm/)

## REVSTEALER malware leaves hidden programs behind after “self-deleting”

![Spf Record Example 3930](https://media.mailhop.org/autospf/spf-record-example-3930-1788955264518.jpg)

Elastic Security Labs documented four previously unreported programs associated with [REVSTEALER](https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html), an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself, with one of them disabling Windows Update and Microsoft Defender before running a **cryptocurrency** miner. [Source: The Hacker News](https://thehackernews.com/)

## A Microsoft 365 “Direct Send” bypass lets attackers spoof internal users with no credentials

_A flaw in Microsoft 365’s Direct Send feature allows attackers to spoof internal-looking emails without needing any valid credentials at all — a serious boost for phishing campaigns since messages appear to come from a trusted colleague or department_. [Source: GBHackers](https://gbhackers.com/microsoft-365-security-bypass/)

## Hackers stole Claude AI session cookies to hijack accounts

A new infostealer campaign is specifically targeting and stealing session cookies for [Claude AI accounts](https://startupfortune.com/hackers-are-draining-claude-subscribers-usage-without-stealing-a-password/), letting attackers hijack sessions and bypass [multi-factor authentication](https://www.onelogin.com/learn/what-is-mfa/) entirely — since a stolen session cookie doesn’t need a **password or MFA code** at all. [Source: GBHackers](https://gbhackers.com/hackers-use-infostealer-malware-to-steal-claude-session-cookies/)

## Attackers sent malicious Excel files to 80,000 freelancers using 255 fake accounts

A large-scale campaign used 255 fake accounts to blast malicious Excel files at roughly [80,000 freelancers](https://www.tomshardware.com/tech-industry/cyber-security/russian-hacker-faces-up-to-20-years-in-prison-following-extradition-and-indictment-over-us-phishing-campaign-that-allegedly-infected-80-000-pcs-hacker-stole-victims-data-via-remote-access), showing how the **gig-economy workforce** — often without enterprise-grade email filtering — makes an attractive, broad target for mass malware delivery. [Source: GBHackers](https://gbhackers.com/excel-malware-campaign/) ![Spf Lookup 2220](https://media.mailhop.org/autospf/spf-lookup-2220-1788954799566.jpg)

## Hackers posed as IT support on Microsoft Teams to target 150+ employees

A [social-engineering campaign](https://www.itnews.com.au/news/us-and-allies-say-russian-hackers-stole-emails-without-social-engineering-627628) impersonated internal IT helpdesk staff over **Microsoft Teams** to target more than 150 employees at a single organization — the same “fake IT support” pretext that has proven effective against major companies over the past year. [Source: GBHackers](https://gbhackers.com/microsoft-teams-it-support-scam/)

## A fake acquisition scam used forged NDAs to demand a €626,000 payment

Business email compromise crews are refining their pretexts: one campaign used a fabricated company-acquisition scenario, complete with forged NDAs, to try to trick a target company into [wiring €626,000](https://gbhackers.com/fake-acquisition-scam/) to attacker-controlled accounts. [Source: GBHackers](https://gbhackers.com/fake-acquisition-scam/)

## QR-code phishing (“quishing”) hit record levels

Attackers are increasingly hiding [malicious links](https://www.firstpost.com/world/china-denies-link-to-seized-iran-bound-ship-calls-claims-malicious-linking-and-hype-14002821.html) inside QR codes to sidestep **traditional link-scanning** email defenses, and this tactic has now hit record volume — a reminder that any [QR code](https://www.infosecurity-magazine.com/news/fbi-warns-north-korean-qr-phishing/) in an unsolicited email or text should be treated with the same suspicion as a raw link. [Source: GBHackers](https://gbhackers.com/qr-codes-attack/)

## Hackers compromised more than 14,500 Dahua security cameras

A mass-exploitation campaign compromised over [14,500 internet-connected Dahua security cameras](https://www.securityweek.com/threat-actor-hacks-14000-ip-cameras-in-ukraine-and-russia/), building a ready-made pool of hijacked [IoT](https://www.ibm.com/think/topics/internet-of-things) devices that can be repurposed for botnets, proxying attack traffic, or further reconnaissance. [Source: GBHackers](https://gbhackers.com/dahua-security-cameras/)

As AI-powered attacks, phishing, and BEC campaigns continue to evolve, strong [SPF](https://autospf.com/blog/10-reasons-the-spf-standard-is-essential-for-protecting-your-domain/), [DKIM](https://autospf.com/blog/tls-and-dkim-why-both-needed-for-strong-email-security/), and [DMARC](https://autospf.com/blog/from-monitoring-to-enforcement-building-a-scalable-dmarc-strategy/) protections are becoming increasingly important for organizations seeking to strengthen [email security](https://autospf.com/) and **prevent domain spoofing**.

![Brad Slavin](https://media.mailhop.org/autospf/images/authors/brad-slavin.jpg) 

[ Brad Slavin ](/authors/brad-slavin/) 

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for AutoSPF's 2,000+ customer base.

[LinkedIn Profile →](https://www.linkedin.com/in/bradslavin) 

## Ready to get started?

Try AutoSPF free — no credit card required.

[ Book a Demo ](/book-a-demo/) 

Scan Your Domain Now

Instantly scan your domain for DKIM, SPF, and DMARC issues

Check My Domain 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fautospf.com%2Fblog%2Faurora-uses-cursor-astra-creates-exploits-enterprise-network-breached%2F) [ ](https://twitter.com/intent/tweet?text=Aurora%20Uses%20Cursor%2C%20Astra%20Creates%20Exploits%2C%20Enterprise%20Network%20Breached%20%20&url=https%3A%2F%2Fautospf.com%2Fblog%2Faurora-uses-cursor-astra-creates-exploits-enterprise-network-breached%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fautospf.com%2Fblog%2Faurora-uses-cursor-astra-creates-exploits-enterprise-network-breached%2F) Copy 

Related Articles

- [ ![DIY-ing SPF](https://media.mailhop.org/autospf/images/2024/04/spf-record-example-5874.jpg)  10 Reasons Why DIY-ing SPF isn’t a Good Choice for Companies Intermediate ](/blog/10-reasons-diy-ing-spf-isnt-good-choice-for-companies/)
- [ ![phishing actors](https://media.mailhop.org/autospf/images/2025/11/spf-record-checker-0096.jpg)  The 12.4 billion shield for your email communications: Why DMARC software is the unsung hero in the war against phishing actors! Intermediate ](/blog/12-4-billion-dmarc-software-shield-protecting-email-from-phishing-actors/)
- [ ![421 Error SMTP Guide](https://media.mailhop.org/autospf/spf-lookup-1607-1785756872932.jpg)  421 Error SMTP Survival Guide: Fix the 4.4.2 Connection Dropped Issue Intermediate ](/blog/421-error-smtp-survival-guide-fix-connection-dropped-email-issue/)
- [ ![Sender Policy Framework](https://media.mailhop.org/autospf/images/2024/11/spf-checker-4785.jpg)  5 key contributors to the development of the Sender Policy Framework Intermediate ](/blog/5-key-contributors-to-sender-policy-framework-development/)

## Related Articles

[  Intermediate 6m  10 Reasons Why DIY-ing SPF isn’t a Good Choice for Companies  Apr 4, 2024 ](/blog/10-reasons-diy-ing-spf-isnt-good-choice-for-companies/)[  Intermediate 5m  The 12.4 billion shield for your email communications: Why DMARC software is the unsung hero in the war against phishing actors!  Nov 19, 2025 ](/blog/12-4-billion-dmarc-software-shield-protecting-email-from-phishing-actors/)[  Intermediate  421 Error SMTP Survival Guide: Fix the 4.4.2 Connection Dropped Issue  Aug 3, 2026 ](/blog/421-error-smtp-survival-guide-fix-connection-dropped-email-issue/)[  Intermediate 3m  5 key contributors to the development of the Sender Policy Framework  Nov 12, 2024 ](/blog/5-key-contributors-to-sender-policy-framework-development/)

```json
{"@context":"https://schema.org","@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138897474","https://www.linkedin.com/company/autospf","https://x.com/autospf01","https://www.g2.com/products/autospf/reviews"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://autospf.com/contact-us/"},"knowsAbout":["SPF Record Flattening","Sender Policy Framework","Email Authentication","DNS Management","DMARC","DKIM"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"AutoSPF","url":"https://autospf.com","description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","publisher":{"@type":"Organization","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Aurora Uses Cursor, Astra Creates Exploits, Enterprise Network Breached  ","description":"Explore the top cybersecurity news from September 1–7, covering AI-powered attacks, zero-days, ransomware, phishing, BEC, and email security threats.","url":"https://autospf.com/blog/aurora-uses-cursor-astra-creates-exploits-enterprise-network-breached/","datePublished":"2026-09-09T00:00:00.000Z","dateModified":"2026-09-09T00:00:00.000Z","dateCreated":"2026-09-09T00:00:00.000Z","author":{"@type":"Person","@id":"https://autospf.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://autospf.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin is the founder and General Manager of DuoCircle, the company behind AutoSPF, DMARC Report, Phish Protection, and Mailhop. He founded DuoCircle in 2014 to solve the SPF 10-DNS-lookup problem at scale and has led the company's growth to 2,000+ customers. Brad's focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement) rather than hands-on DNS engineering.","image":"https://media.mailhop.org/autospf/images/authors/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"AutoSPF","url":"https://autospf.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138897474","https://www.linkedin.com/company/autospf","https://x.com/autospf01","https://www.g2.com/products/autospf/reviews"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://autospf.com/contact-us/"},"knowsAbout":["SPF Record Flattening","Sender Policy Framework","Email Authentication","DNS Management","DMARC","DKIM"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://autospf.com/blog/aurora-uses-cursor-astra-creates-exploits-enterprise-network-breached/"},"articleSection":"intermediate","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/autospf/spf-lookup-6402-1788959755029.jpg","caption":"AI Cybersecurity Threat Report"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://autospf.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://autospf.com/blog/"},{"@type":"ListItem","position":3,"name":"Intermediate","item":"https://autospf.com/intermediate/"},{"@type":"ListItem","position":4,"name":"Aurora Uses Cursor, Astra Creates Exploits, Enterprise Network Breached  ","item":"https://autospf.com/blog/aurora-uses-cursor-astra-creates-exploits-enterprise-network-breached/"}]}
```
