Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.
Cisco Talos Releases Open-Source Tool to Track Malware That Takes Orders From AI Chatbots

Cisco Talos researchers released an open-source framework Monday called the Cognitive Artifact Intelligence Research Network, or CAIRN, built to track a new kind of malware that doesn't just run pre-written code. It asks an AI chatbot what to do next.
According to Wired, the tool is designed to flag AI-integration fingerprints left behind in malware code and metadata, then tag and classify each sample so researchers can compare it against everything else in the CAIRN library. Ryan Fetterman, the Cisco Talos security researcher who led the project, described the logic simply: "The core idea is that AI integration has these vestiges, like fingerprints, that are left behind. That gives us a signal that we can use to track these samples, classify them, and look at what's happening."
The tool already found something. Cisco Talos used CAIRN to identify a hacking tool dubbed CLOSEDQUORUM, which Wired reports runs on fully autonomous command-and-control infrastructure. Instead of getting orders from a human operator, the malware polls up to four separate large language models and takes its next move from that collective output, essentially letting an AI hive mind run the operation with no person directing it in real time.
This isn't the first AI-driven malware anyone has spotted. In July 2025, Ukraine's cybersecurity response unit, CERT-UA, warned about a phishing campaign using malware called LAMEHUG, which communicated with an LLM named Qwen2.5-Coder-32B-Instruct through a Hugging Face API to receive its commands, according to Wired's reporting on the Cisco Talos findings.
At the time, Fetterman expected that case to be the start of something big. "Wow, this is amazing," he recalled thinking. "There's gonna be this big boom of AI-enabled malware and the landscape is totally going to change."
The boom that didn't happen, yet
A year later, when Fetterman ran a retrospective this summer looking for AI-integrated malware families, he came up mostly empty. "There really wasn't a lot there," he told Wired. "I think I came up with maybe nine different named malware families," and some of those, he noted, were proof-of-concept samples built by researchers rather than real attackers.
A gap exists between the doom-and-boom prediction and the documented reality. A year after the first publicly flagged case, real-world AI-guided malware remained rare enough that one researcher could count the known families on two hands. The alarm sounded in mid-2025 didn't translate into a wave of confirmed attacks by 2026, at least not one visible in Cisco Talos's dataset.
Fetterman's own reaction to that gap is telling. He said he had "a hard time believing that that was the reality of where we were," which is why he built CAIRN in the first place to dig past anecdotal case counts and get a systematic way to spot AI-integration artifacts that might otherwise slip past manual detection.
Cisco Talos is releasing CAIRN as open source specifically so other defenders, not just Cisco's own team, can classify samples and share findings. Fetterman's stated goal is turning anecdote into data: tracking what attackers are actually trying with AI tools, and what emergent behaviors show up as more malware authors experiment, rather than relying on scattered case reports like the LAMEHUG warning from CERT-UA. Whether that broader adoption happens, and whether the malware count climbs beyond nine documented families in the next year, is the open question CAIRN is designed to answer.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.