Cisco Talos Finds CLOSEDQUORUM Malware Run by an AI Hive Mind of Four LLMs
nordicinst · x · 2026-09-22
Cisco Talos released CAIRN, an open-source framework for detecting and classifying malware that integrates AI chatbots, exploiting the 'fingerprints' AI integration leaves behind. Using it, researchers discovered CLOSEDQUORUM, a hacking tool with fully autonomous command-and-control that polls up to four LLMs—a hive mind—to decide its moves inside a target system, with no humans in the loop. A sign agentic AI is now live in attack tooling.
More from Safety
- The week labs asked to slow down: Claude does 26% of Anthropic's work, Gemini breached 3 firms — alex_verem · 2026-09-22
- Anthropic's 'Constitution' Is Just RLAIF, Argues Researcher — Its Real Benefit Is Cutting Human Labeling — WillRinehart · 2026-09-22
- Amazon backs rigorous AI testing but refuses to support a moratorium on model development — emmanuelvivier · 2026-09-22
- Anthropic and Accenture put $2B into embedded safety evaluators inside model teams — emmanuelvivier · 2026-09-22
- Cisco Talos Uncovers Malware Guided by an AI Hive Mind, No Humans Involved — Wired AI · 2026-09-22
- Book review: 'Silicon Sovereigns' examines AI, international law and the tech-industrial complex — ProfChesterman · 2026-09-22