Cisco Talos disclosed something on September 22 that moves the security threat model forward: CLOSEDQUORUM, which they call the first fully autonomous multi-model AI command-and-control implant that operates with no human operator. This isn't a novel attack vector announced by a researcher. This is a piece of malware that's already in the wild, running autonomously, using multiple AI models to make decisions without anyone at the keyboard.
The shift matters. For the last year or so, AI in cyber has mostly been what you'd call AI-assisted crime. A human operator uses a model to write convincing emails, generate code, or iterate on exploits faster than they could alone. The operator still calls the shots. They still decide what to do. The AI speeds up the thinking.
CLOSEDQUORUM skips the human layer entirely. Command and control that used to require someone monitoring, issuing orders, adapting to responses now runs autonomously. The models inside it make decisions about what to exfiltrate, whether to move laterally, how to respond to defensive moves. No one has to be watching.
Cisco released CAIRN, a toolkit for hunting this specific malware, which is the responsible move. But the release note contains something darker: they describe malware's evolution from optional AI helpers to autonomous command and control as something that happened "within about a year." A year. Not a decade, not a generation. Twelve months from "AI helps attackers work faster" to "AI runs the attack itself."
The technical question is whether CLOSEDQUORUM actually does what Cisco claims, or whether the autonomy is narrower than the framing suggests. Talos is a serious security outfit with a track record of accurate technical disclosure. I'd trust their assessment. But I'd also expect the industry to spend the next week tearing this apart to figure out exactly what "autonomous" means in practice, is it responding to changed network conditions, or is it making novel strategic decisions? The distinction matters for what comes next.
What's harder to predict is whether this changes the conversation at policy level. The UN Security Council is meeting today in Paris, with OpenAI, Anthropic, DeepSeek, and Moonshot representing the major labs. The SecretaryTreasury has a seat. This disclosure lands in that exact moment. A fully autonomous malware running multiple models is exactly the kind of concrete incident that makes abstract governance conversations real.
For defenders, the immediate play is clear: deploy CAIRN, hunt your systems, see if CLOSEDQUORUM is already inside. For executives and CISOs, the harder question is structural. If autonomous malware is now possible, then the models that run it are the threat. Not the humans holding the keyboard anymore, the AI itself.
That's the bit that doesn't have an answer yet.
Top comments (0)