What happened
- On September 22, 2026, Cisco Talos published its report on CAIRN, an in-house tool for tracking malware that integrates or attacks AI systems, along with its first findings.
- The main one is CLOSEDQUORUM, which Talos describes as the first reported implant with autonomous AI-based command and control: an orchestrator that queries several models and decides by consensus, with no human operator behind it.
- CAIRN’s filters look for traffic to endpoints from OpenAI, Anthropic, DeepSeek and Google. The analysis is done on metadata, without downloading or running the binaries.
- Talos also describes an escalation arc: from basic language model integrations to full autonomy within a year, counting from July 2025.
Why it matters
- Traffic to commercial model APIs has stopped being a sign that someone in the organization is trying out tools. It can be an implant’s command channel, and today it runs through the same domains the company has just authorized.
- Without a human operator there are no working hours or time zone to give the operation away, and the typo that attribution usually relies on disappears. Detection teams in the region work with small staffs and with rules that assume exactly those clues.
- Talos documents that AI-specific evasion techniques spread among independent actors within twelve months. That’s the real adaptation timeline, not the annual audit cycle.
The number
4 model providers (OpenAI, Anthropic, DeepSeek and Google) appear in the filters CAIRN uses to look for this kind of malware. It’s the map of what currently serves as a command channel.
Context
In August we noted that AI agents are already attacking real systems and security is no longer a detail. Weeks later Anthropic had to close Claude sessions stolen by malware. CLOSEDQUORUM reverses the relationship: AI isn’t the target; it’s the attacker’s infrastructure.
What’s next
- CAIRN is available as a research tool. Talos didn’t announce a date for new reports in the series.
- No timelines announced by the model providers named regarding detection of this use on their APIs.
Bottom line
Last year the debate about offensive agents was a projection used to justify budgets. Now there’s a name, a dated report and a list of domains to check in the egress logs.
Sources
Edited by Rodrigo Cornejo. How we select and verify each fact is in who writes.


