Find notable cyber news and cases, enriched with sources, timelines, and signals.

Cisco Talos releases CAIRN open-source tool for hunting malware that uses AI services

Security Tool/Service
First reported
Last updated
Happening score
H score 11
1 unique sources, 1 articles

Summary

Hide ▲

Cisco Talos released CAIRN, an open-source tool that hunts malware that uses AI services, adding a new detection capability for implants that route decisions through commercial AI platforms. The release matters because it gives defenders a dedicated way to spot a growing malware technique that can blend into normal cloud and AI traffic.

Related Happenings

CLOSEDQUORUM Windows AI-model-voting malware

Malware Activity
H score29 First: 23.09.2026 17:17 Last: 23.09.2026 17:17 Sources 1

How related: A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22.

About this happening: The CLOSEDQUORUM malware now uses votes from up to four AI models to choose steal, inject, persist, or move actions, replacing a normal attacker C2 flow on Windows...

UAT-11795 Starland RAT trojanized installer malware activity

Malware Activity
H score31 First: 16.07.2026 13:19 Last: 16.07.2026 13:19 Sources 1

About this happening: The UAT-11795 malware activity is using trojanized installers to deploy Starland RAT, putting credentials and cryptocurrency wallets at risk across multiple countries....

RondoDox botnet expands mining and DDoS capabilities

Malware Activity
H score31 First: 16.04.2026 20:52 Last: 16.04.2026 20:52 Sources 1

About this happening: RondoDox botnet now combines cryptocurrency mining with XMRig and DDoS attacks, expanding both monetization and disruption risk across exposed systems. It reaches targ...

UAT-9244 South America telecom targeting campaign

Campaign
H score33 First: 06.03.2026 01:19 Last: 06.03.2026 01:19 Sources 1

About this happening: UAT-9244 is a China-linked campaign targeting telecommunication providers in South America since 2024. It compromises Windows, Linux, and edge devices to expand access across tele...

Latest development: 06.03.2026 10:22

The first documented phase centers on TernDoor targeting Windows hosts through DLL side-loading with `wsprint.exe` and `BugSplatRc64.dll`. After launch, it loads in memory and establishes persistence through a scheduled task or the Registry Run key.

VoidLink Linux C2 malware activity

Malware Activity
H score28 First: 09.02.2026 17:25 Last: 09.02.2026 17:25 Sources 1

About this happening: VoidLink is an operational Linux C2 framework used by UAT-9921 as a post-compromise tool against technology and financial services targets. Cisco Talos says th...

Timeline

  1. 23.09.2026 17:17 2 articles · 2h ago

    Cisco Talos releases CAIRN open-source malware hunting tool

    Detection Ioc Update

    Cisco Talos released CAIRN, an open-source tool for hunting malware that uses AI services, and used it to find CLOSEDQUORUM.

    Show sources