Cisco Talos researchers identified a Go-based Windows malware called ClosedQuorum that queries Google Gemini, DeepSeek, Qwen, and Mistral to decide post-compromise actions without human input. The models vote on options such as credential theft, code injection, and persistence, with DeepSeek breaking ties, and stolen data is sent to attackers via a Discord webhook.
Cisco Talos researchers released an open-source system called CAIRN designed to detect and classify malware that relies on artificial intelligence for decision-making. Using the tool, they identified a new strain, CLOSEDQUORUM, which queries up to four large language models to determine its next actions inside a compromised system rather than following pre-programmed commands.
Cisco Talos reported that three distinct threat groups—including Qilin ransomware affiliates and state-sponsored actors—have been exploiting two vulnerabilities in Cisco Secure Firewall Management Center. The flaws, a maximum-severity authentication bypass (CVE-2026-20079) and a static credential issue (CVE-2026-20316), let attackers gain root access, deploy web shells, steal credentials, and in some cases install Qilin ransomware or Cyclops Blink malware. Cisco has issued hot fixes and urges immediate patching, with broader hardening updates planned next week.
Cisco Talos researchers identified two separate ClickFix-style social engineering campaigns that trick victims into executing malicious code themselves, one aimed at stealing cryptocurrency and another designed to gain persistent enterprise network access. One campaign uses a publicly shared Google Sheet to distribute malicious browser code that hijacks Chrome transaction interfaces, while both operations abuse legitimate cloud services and trusted software to disguise malicious activity as normal user behavior.