Cisco / Talos

10 items · Capability 1 · Defense 5 · Attacks 4 · all entities

Talos open-sources a framework for hunting AI-integrated malware

Cisco Talos released CAIRN (Cognitive Artifact Intelligence Research Network), a toolkit that finds candidate samples through up to 24 acquisition filters aimed at AI-related artifacts such as API endpoints, prompt templates, evasion terms and local model runtimes, without executing the binary. Talos says its hunts cover malware development since July 2025, when the first AI-integrated samples were reported in the wild, and that the progression from "LLM as optional feature" to "fully autonomous multi-model consensus orchestrator with no human operator" filled in within a single calendar year.

Reported by researchersCisco Talos ↗ ·

Cisco Talos documents a Windows implant that lets four AI models vote on its next move

Talos describes CLOSEDQUORUM, a 16.4MB 64-bit Windows executable compiled in Go that queries DeepSeek, Qwen, Mistral and Google Gemini and executes whichever post-compromise action wins a plurality vote, with DeepSeek breaking ties; its capabilities include LSASS credential dumping, browser password theft and process injection. Talos calls it "to our knowledge, the first publicly documented Windows implant to apply this model to tactical command and control (C2)" and says "we do not have confirmation of in-the-wild deployment," though binary artifacts tie the developer to carding-forum postings dating to 2025.

Reported by researchersCisco Talos ↗ ·

Cisco confirms active exploitation of a maximum-severity authentication bypass in Identity Services Engine

Cisco published an advisory for CVE-2026-76460, a CVSS 10.0 authentication bypass in an Identity Services Engine API endpoint, saying “The Cisco PSIRT is aware of active exploitation of this vulnerability.” Cisco's source note attributes the find to the resolution of a Technical Assistance Center support case rather than to the AI-assisted testing named in its hardening advisory the same day; fixes are in ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4.

On the recordCisco ↗ ·

Cisco says frontier AI models helped find six Identity Services Engine flaws, four of them rated 9.9 or above

Cisco's September hardening advisory for Identity Services Engine lists six vulnerabilities — CVE-2026-20130 and CVE-2026-20192 at CVSS 10.0, CVE-2026-20234 and CVE-2026-20237 at 9.9, CVE-2026-20194 at 9.1 and CVE-2026-20287 at 6.5 — and states that “These vulnerabilities were found during internal security testing using existing testing processes as well as frontier AI models.” The advisory does not say which flaws came from which process, and names no model or vendor.

On the recordCisco ↗ ·

Cisco argues a model's country label is a poor proxy for its security, and measures inherited lineage

Testing Qwen-derived Nemotron models, Cisco reports that in its own 184-model catalog Qwen made up 12.0% of the pool but 20.9% of nearest neighbours, a 1.74 times base rate, and in VAIL's 1,159-model catalog 14.9% against 28.1%, a 1.89 times rate. It concludes that post-training and a new publisher name do not necessarily erase detectable relationships to an upstream model family, and that geographic labels are an incomplete proxy for AI risk.

Self-reported, untestedCisco ↗ ·

OpenAI leads more than 100 companies in an open letter calling for collective AI cyber defense

OpenAI published an open letter, co-signed by more than 100 organizations including Anthropic, Google, Microsoft, AWS, Oracle, Cisco, Cloudflare, CrowdStrike, Palo Alto Networks and Hugging Face, calling for collective action to defend against sustained AI-enabled attacks. It urges every organization to make cyber defense an immediate leadership priority and fix its highest-risk weaknesses, asks security and frontier-AI companies to give under-resourced defenders responsible model access, funding and threat-intelligence sharing, and asks governments to coordinate cyber defense across levels and fund essential services that lack the staff or budget.

On the recordOpenAI (open letter, 100+ signatories) ↗ ·

Cisco Talos finds a Chinese-speaking crew running agentic-AI tools in live post-compromise operations

Cisco Talos reported that the threat actor it tracks as UAT-10147 had AI tooling installed on its own management and command-and-control servers: DeepAudit for source-code vulnerability scanning, PentestGPT to dynamically scan web servers and run proof-of-concept exploits, and ysoserial output paired with AI-generated documentation and Python automation scripts for reconnaissance, implant deployment and shell establishment. Talos recovered the operators' own guides, scripts and findings logs and assessed the AI use as observed rather than inferred, though it did not see exploitation driven by DeepAudit's results.

Reported by researchersCisco Talos ↗ ·

Cisco Talos analyses prompt logs recovered from threat actors' own machines

Talos examined a corpus of prompt logs left by Claude Code, CodeX, Cursor and Gemini on threat actor endpoints, grouping the use into AI as a malicious software engineer, AI for scaling criminal operations and AI for vulnerability research. It reports it “did not encounter any sophisticated encoding or techniques designed to trick the models” — claims of equipment ownership, capture-the-flag or bug-bounty framing, splitting risky actions across sessions and neutral verb choice were enough — and concludes “guardrails are not functioning as expected.”

Reported by researchersCisco Talos ↗ ·

One malicious agent skill got past all eight open-source skill scanners tested

Adversa AI tested a malicious skill against Cisco skill-scanner, NVIDIA SkillSpector, mondoo skillcheck, skillcop, claude-skill-antivirus, huifer skill-security-scan, ai-skill-scanner and hackmyagent, and reports it bypassed all eight, each through a different evasion. It attributes the common failure to a missing preprocessing step: “every scanner matches the bytes in the file, not the bytes that execute,” and none decodes an encoded payload and re-runs its full ruleset over the plaintext or normalises Unicode first.

Self-reported, untestedAdversa AI ↗ ·

NVIDIA, Microsoft, IBM, Cisco and Cloudflare launch the Open Secure AI Alliance

Thirty-seven inaugural partners — including NVIDIA, Microsoft, Adobe, Cisco, Cloudflare, Databricks, Hugging Face, IBM, Palantir, Palo Alto Networks, Red Hat, Salesforce, SAP and Snowflake, with the Linux Foundation among them — launched an alliance to share open technology for securing software and agents, contributing working code rather than recommendations: NVIDIA's NOOA agent-harness research, HPE on SPIFFE/SPIRE agent identity, Hugging Face's Safetensors, IBM and Red Hat's signed-patch supply-chain tooling, and Microsoft's MDASH scanning harness. Member counts differ between the founding announcements; the press framing that it was formed in response to the Hugging Face incident is not in NVIDIA's own post.

On the recordNVIDIA ↗ ·