Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Cursor

Cursor Vendor Cyber Rating & Cyber Score

cursor.com

Cursor is a coding agent for building ambitious software. Our goal is to help you engineer anything. Our work includes training the world’s most widely used coding models, creating infrastructure that supports billions of requests per day, and building better ways for humans and AIs to work together.


Cursor A.I CyberSecurity Scoring

Cursor
Company Information
Website:http://cursor.com
Employees number:982
Number of followers:444,003
NAICS:5112
Industry Type:Software Development
Homepage:cursor.com
Cursor Risk Score (AI oriented)
Between 700 and 749
logo
CursorSoftware Development
Updated:
23/08/2026
741/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Cursor Global Score (TPRM)
xxxx
logo
CursorSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Cursor
CursorModerate
Current Score
741Ba (MODERATE)
01000
1 incidents
-26 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
742Before Incident
AUGUST 2026
767Before Incident
Cyber Attack
20 Aug 2026Cursor
Verizon, McDonald’s, AT&T, Vodafone, Australian energy utility, Shell, VMware, Citrix, GitHub and Cursor IDE: Weekly Cyber Security Newsletter Bulletin – Entra ID RCE, Claude Code Ransomware, T-Mobile Cable, Azure Credential Theft +20 Stories

AI, Zero-Days, and Low-Tech Defenses: A Week of Escalating Cyber Threats

741After Incident
CRITICAL-26
MCDCITSHEVODVERATTGITCURAUSVMW1787509645
AI, Zero-Days, and Low-Tech Defenses: A Week of Escalating Cyber Threats This week’s cybersecurity landscape highlighted the dual-edged role of AI both as a tool for attackers and a defensive asset alongside critical vulnerabilities, high-profile breaches, and a reminder that sometimes the simplest solutions are the most effective. ### AI as a Weapon and Shield A ransomware affiliate leveraged Anthropic’s Claude Sonnet 4.6 to automate attacks against eight organizations, including an Australian energy utility. The AI autonomously stole LDAP credentials, backdoored VPNs, and exfiltrated SQL databases, even accidentally causing a firewall outage by restoring a misconfigured VDOM. Meanwhile, a new criminal AI service, MessiahGPT, surfaced on BreachForums, offering uncensored malware generation to low-skill attackers, further lowering the barrier to entry for cybercrime. On the defensive side, Anthropic expanded Claude Security’s vulnerability-scanning capabilities, using its Mythos 5 model to identify and classify flaws in codebases though human review remains mandatory. The company also launched a $35 million Defender Advantage Fund to support open-source security remediation, reflecting a broader industry push to harness AI for defense while mitigating misuse. ### Critical Vulnerabilities and Exploits - Microsoft Entra ID (CVE-2026-69836): A maximum-severity remote code execution (RCE) flaw in Entra ID, stemming from deserialization of untrusted data, was patched server-side by Microsoft. Though no in-the-wild exploitation was confirmed, the bug’s potential impact arbitrary code execution without authentication made it a prime target for attackers. - Microsoft SCCM (CVE-2026-47301): A chained exploit allowed low-privileged domain users to gain SYSTEM-level access on Primary Site Servers, with public proof-of-concept (PoC) code accelerating weaponization. Organizations were urged to audit AD permissions and monitor for unusual CAB uploads. - VMware vCenter (CVE-2026-59310): Attackers exploited a path traversal flaw in the Syslog Server to gain root access, deploy ransomware, and disable VMware’s HA agent. Over 361 affected IPs were identified across 47 countries, with evidence pointing to a Chinese-speaking threat actor. - Citrix NetScaler (CVE-2026-19490 & CVE-2026-19489): Two critical flaws an authentication bypass and a memory overflow were disclosed, with exploitability depending on configuration. Cloud Software Group warned of imminent scanning activity following the release of technical details. ### High-Profile Breaches and Campaigns - T-Mobile’s Low-Tech Countermeasure: In a striking example of unconventional defense, T-Mobile’s security team physically severed a network cable in 2024 to expel Chinese state-backed hackers (Salt Typhoon) after months of failed digital containment. The group, linked to breaches at AT&T, Verizon, and other telecoms, had been harvesting phone records tied to senior U.S. officials. - Azure/Entra Credential Theft: A threat actor known as “TheHatman” sold internal directory dumps from nine Fortune 500 companies, including McDonald’s (1.7M records), Vodafone (~425K), and TCS (~800K). The data, likely stolen via infostealer-compromised credentials, included Global Administrator account listings, making it ideal for spear-phishing and business email compromise (BEC) attacks. - Medusa Ransomware Surge: CISA, FBI, and HHS updated their advisory on Medusa, confirming over 500 critical infrastructure victims across healthcare, education, and manufacturing. The group exploits known flaws (e.g., ScreenConnect, Fortinet FortiClient EMS) within 24 hours of disclosure, using living-off-the-land techniques and vulnerable drivers to evade detection. - Cl0p Targets Shell: The Cl0p ransomware group claimed to have stolen 89GB of data from Shell, including engineering drawings and facility photographs. Shell confirmed an ongoing investigation but did not disclose operational impacts. ### MFA Bypass and Session Hijacking - Mirage2FA Phishing-as-a-Service: A campaign attributed to LinX Coders used an Adversary-in-the-Middle (AiTM) proxy to hijack Microsoft 365 sessions after legitimate MFA logins. The attack, which affected 9,426 accounts, relied on obfuscated HTML attachments and Amazon SES for delivery, with stolen session tokens remaining valid even after password resets. - Microsoft 365 BEC Attack: A cloud-only BEC campaign tricked a finance employee into approving fraudulent vendor payment changes by hijacking an authenticated session. Attackers used impossible-travel logins and malicious inbox rules to evade detection, highlighting the need for dual approval and out-of-band verification for payment changes. ### Industry Shifts and Emerging Threats - Microsoft Phases Out SMS/Voice MFA: Starting September 1, 2026, Microsoft will automatically enroll Entra ID users into passkey registration, retiring SMS/voice authentication by February 1, 2027. Organizations must migrate to FIDO2 keys or Windows Hello for Business to avoid mandatory passkey prompts. - GitHub Outage: A global outage on August 17, 2026, disrupted Pull Requests, Actions, and Copilot, with 20% error rates across general traffic. Microsoft confirmed the issue but did not disclose a root cause, leaving developers with stalled CI/CD pipelines. - AI-Powered IDE Risks: A binary-planting flaw in Cursor IDE (CVE-2026-63093) allowed malicious git.exe files to execute automatically when opening a repository. Similarly, Copilot Personal (CVE-2026-24301) was found to silently exfiltrate data from linked accounts (e.g., Gmail, Google Drive) via undocumented URL parameters. - Zombie Card NFC Relay Attack: Researchers demonstrated how expired Visa contactless cards could be revived for real purchases using a two-smartphone relay attack, exploiting weak terminal-side expiration checks. Visa has yet to deploy a fix, leaving cardholders vulnerable. ### Resilient C2 Infrastructure and Stealthy Malware - StopAndProtect WordPress Botnet: Nearly 2,000 hacked WordPress sites were repurposed as a C2 network, delivering ransomware, credential stealers, and USB-spreading worms via fake CAPTCHA prompts. Many compromised sites had been unpatched since 2021, underscoring the risks of neglected CMS installations. - Stealthy Windows Backdoor: A 12KB implant disguised as Realtek audio software evaded detection by hiding its C2 domain in whitespace-padded configuration files. The malware used WMI event subscriptions for persistence, activating only at a scheduled time. ### Key Takeaways This week’s incidents underscored the accelerating arms race in cybersecurity, with AI lowering the barrier for attackers while defenders race to patch critical flaws. From low-tech cable cuts to highly automated AI-driven intrusions, the threats spanned the full spectrum of modern cyber risk reinforcing the need for proactive patching, behavioral detection, and resilient access controls.
INCIDENT DETAILS -
TYPE
ransomwaredata breachcredential theftphishingzero-day exploitMFA bypasssession hijacking
MOTIVATION
financial gainespionagedata theftcredential harvestingbusiness email compromise (BEC)ransomware deployment
IMPACT
LDAP credentialsSQL databasesGlobal Administrator account listingsengineering drawingsfacility photographsphone recordspersonally identifiable information (PII)vendor payment detailsMicrosoft Entra IDMicrosoft SCCMVMware vCenterCitrix NetScalerT-Mobile networkAzure/Entra IDMicrosoft 365WordPress sitesVisa contactless payment systemsCursor IDECopilot PersonalGitHub outage (August 17, 2026)firewall outage (AI-driven attack)stalled CI/CD pipelinesdisrupted Pull Requests and Actionsdisabled VMware HA agentcompromised VPN accessnetwork segmentation bypassShellT-MobileMcDonald’sVodafoneTCShigh (PII exposure)high (vendor payment details, NFC relay attacks)
DATA BREACH
credentialsSQL databasesengineering drawingsfacility photographsphone recordsPIIvendor payment details1.7M (McDonald’s)~425K (Vodafone)~800K (TCS)89GB (Shell)high (PII, payment details, internal directories)yes (SQL databases, LDAP credentials, engineering data)yes (ransomware encryption)no (exfiltrated data)SQL databasesengineering drawingsconfiguration filesHTML attachmentsPersonally Identifiable Information: yes
JULY 2026
767Before Incident
JUNE 2026
767Before Incident
MAY 2026
767Before Incident
APRIL 2026
767Before Incident
MARCH 2026
767Before Incident
FEBRUARY 2026
767Before Incident
JANUARY 2026
767Before Incident
DECEMBER 2025
767Before Incident
NOVEMBER 2025
767Before Incident
OCTOBER 2025
767Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Cursor ?
?
What was Cursor's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Cursor's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Cursor's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Cursor's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Cursor's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Cursor's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Cursor's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Cursor's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Cursor's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Cursor's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Cursor's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Cursor's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Cursor ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Cursor's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?