Cybersecurity startup Gambit says a financially motivated threat actor has been using open-source AI agent tools since July to attack online retailers at scale, breaching at least 27 companies in a five-day span and launching over 100 attacks. The operation reportedly stole more than 600,000 valid card records from two companies and planted skimmer malware on five others, using three tools—Strix for scanning, Cairn for exploitation, and Hermes, powered by Claude Opus 4.6, for orchestration and tactical decisions.
bleepingcomputer.com
· 2026-09-23
Cisco Talos researchers identified Windows malware named CLOSEDQUORUM that consults DeepSeek, Qwen, Mistral and Google Gemini to decide its next actions on infected machines, continuing to function if one service goes down. The tool, designed to steal credentials and cryptocurrency, has no built-in mechanism for human operators to issue commands directly, and Talos linked it to 2025 credit-card fraud forum activity, though the creator and any real-world targets remain unidentified.
techspot.com
· 2026-09-23
Cisco Talos researchers released an open-source system called CAIRN designed to detect and classify malware that relies on artificial intelligence for decision-making. Using the tool, they identified a new strain, CLOSEDQUORUM, which queries up to four large language models to determine its next actions inside a compromised system rather than following pre-programmed commands.
wired.com
· 2026-09-22