{"id":218,"date":"2026-09-24T10:10:20","date_gmt":"2026-09-24T10:10:20","guid":{"rendered":"https:\/\/scoy.ai\/guides\/ai-news-roundup-september-24-autonomous-ai-malware-quorum\/"},"modified":"2026-09-24T10:13:32","modified_gmt":"2026-09-24T10:13:32","slug":"ai-news-roundup-september-24-autonomous-ai-malware-quorum","status":"publish","type":"post","link":"https:\/\/scoy.ai\/guides\/ai-news-roundup-september-24-autonomous-ai-malware-quorum\/","title":{"rendered":"AI News Roundup for September 24: Cisco Talos Found Malware That Lets Four AI Models Vote on Its Next Move"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Two of today&#8217;s stories are the same story wearing different clothes. On Tuesday Cisco Talos documented a Windows implant that asks four commercial AI models what to do next, and on Wednesday the two CEOs whose models were absent from that list stood in front of the UN Security Council asking for international rules.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Malware That Outsources Its Next Move to a Vote<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Cisco&#8217;s Talos group <a href=\"https:\/\/blog.talosintelligence.com\/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant\/\" target=\"_blank\" rel=\"noopener\">published its teardown<\/a> of an implant it calls CLOSEDQUORUM, which it describes as the first reported autonomous AI command and control implant. The mechanism is the part you need to understand. Once the implant lands on a host, it stops waiting for a human operator and instead polls up to four commercial models, DeepSeek, Qwen, Mistral and Google Gemini, asking each to pick the next post-compromise action from a prewritten list. Each active model votes, and the action with the most votes wins. Ties break in a fixed order, with DeepSeek first and Gemini last.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The rest of the specification is ordinary criminal work. Talos describes a 16.4MB 64-bit Windows executable compiled in Go that dumps LSASS, lifts saved credentials out of Chrome, Edge and Firefox, and goes after MetaMask, Exodus and Ethereum wallets. Development builds inject provider API keys at compile time. The publicly circulated sample ships with a placeholder key, so what Talos analysed is the plumbing rather than a live operation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here is the detail nobody else pulled out, and I checked it against the Talos writeup directly rather than the coverage: no OpenAI model and no Anthropic model appears in that quorum. Resist the flattering explanation. One sample is not a safety league table, and the likelier reading is mundane, because the four chosen providers are the ones with the cheapest keys and the least friction for an attacker who needs volume and does not want a billing relationship that leads anywhere. Talos also shipped a defensive toolkit alongside the research, an open-source project called CAIRN for hunting AI-integrated malware, which is the more useful half of the announcement if you run detection. If you have been tracking how fast this category moves, this sits directly downstream of <a href=\"https:\/\/scoy.ai\/guides\/ai-news-roundup-september-20\/\">the zero-click bug that hit four coding agents<\/a> last weekend.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Triage: breaks your stack.<\/strong> Your egress filtering probably treats api.deepseek.com and generativelanguage.googleapis.com as ordinary SaaS. They are now a command channel.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Altman and Amodei Asked the Security Council for Rules<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">France used its rotating presidency to put AI in front of the Security Council on Wednesday. Altman appeared in New York and Amodei joined by video link, and both argued the industry cannot set its own terms alone. Amodei told the council that if managed poorly he believed AI could be a risk to humanity as a whole, and put three mechanisms on the table: narrow global agreements such as a ban on using AI to build biological weapons, verification systems so states can check each other&#8217;s commitments, and shared testing standards with a notification channel for AI security incidents. Altman&#8217;s framing was blunter, telling the council that if AI is to be democratic then the most important decisions cannot be made by labs in San Francisco alone. Yoshua Bengio, who co-chairs the UN&#8217;s independent scientific panel, told the room the dangers are real and imminent.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then the United States killed it in one sentence. Michael Kratsios, speaking for the administration, said Washington totally rejects all efforts by international bodies to assert centralised control and global governance of AI, as <a href=\"https:\/\/www.aljazeera.com\/news\/2026\/9\/24\/ai-corporate-leaders-tell-un-the-industry-needs-global-regulation\" target=\"_blank\" rel=\"noopener\">Al Jazeera&#8217;s account of the session<\/a> records. That is the whole story. Nothing binding is coming out of a Security Council where a permanent member has pre-rejected the premise, and the labs know it, which is why the same week produced a proposal for a voluntary industry standards body modelled on FINRA instead.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"LIVE: UN Security Council Discusses AI as Sam Altman, Dario Amodei &amp; Yoshua Bengio Speak\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/thfkQBuW4Z0?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\">ANI News, September 23: the full Security Council session, with Altman, Amodei and Bengio speaking.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Triage: matters.<\/strong> Not because regulation is imminent. It matters because the labs have now publicly accepted that voluntary standards are the only instrument available, and voluntary standards are the ones you will be audited against by your own enterprise customers.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Four Things Opus 5.5 Breaks in Code That Already Runs<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">I covered <a href=\"https:\/\/scoy.ai\/guides\/ai-news-roundup-september-23\/\">the price cuts yesterday<\/a> and will not relitigate them. What the pricing coverage buried is that <a href=\"https:\/\/platform.claude.com\/docs\/en\/models\/opus-5-5\/whats-new-opus-5-5\" target=\"_blank\" rel=\"noopener\">Anthropic&#8217;s own documentation<\/a> lists four breaking changes for anyone moving an agent from Opus 5, plus a fifth change that breaks nothing and silences your UI.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>What changed<\/th><th>What happens<\/th><th>What to do<\/th><\/tr><\/thead><tbody><tr><td>Thinking cannot be disabled<\/td><td><code>thinking: {\"type\": \"disabled\"}<\/code> returns a 400<\/td><td>Omit the field, control depth with <code>effort<\/code><\/td><\/tr><tr><td>Forced tool use removed<\/td><td><code>tool_choice<\/code> of <code>any<\/code> or <code>tool<\/code> returns a 400<\/td><td>Use <code>auto<\/code> plus strict tool use<\/td><\/tr><tr><td>Thinking blocks bound to model<\/td><td>Blocks from Fable or Mythos get dropped<\/td><td>Keep conversations append-only<\/td><\/tr><tr><td><code>computer_20251124<\/code> rejected<\/td><td>400 on Claude API and Google Cloud<\/td><td>Move to <code>computer_toolset_20260801<\/code><\/td><\/tr><tr><td>Default effort is now <code>medium<\/code><\/td><td>Was <code>high<\/code> on Opus 5, so quality shifts silently<\/td><td>Set <code>effort<\/code> explicitly and re-run your sweep<\/td><\/tr><\/tbody><\/table><figcaption class=\"wp-element-caption\">Anthropic&#8217;s documented breaking changes for Claude Opus 5.5, plus the effort default that changes behaviour without raising an error.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Two more things will bite you and neither raises an error. Text the model writes between tool calls now arrives inside thinking blocks that are empty at the default display setting, so an agent that streamed those notes as progress updates goes quiet with nothing in the logs. And a refused request comes back as HTTP 200 with <code>stop_reason<\/code> set to refusal, not as a 4xx, so any retry logic keyed on status codes will record a success and move on.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Triage: breaks your stack.<\/strong> Pin <code>claude-opus-5-5<\/code> explicitly. Aliases resolve at request time and Sonnet 5.5 and Haiku 5.5 are landing in the coming weeks.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What I Am Watching<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Marketing award of the day goes to Salesforce, which opened Dreamforce by announcing that <a href=\"https:\/\/www.salesforceben.com\/salesforce-launches-aiforce-at-dreamforce-26-ai-replaces-the-ui\/\" target=\"_blank\" rel=\"noopener\">AI replaces the UI<\/a>. Underneath the slogan sits Headless 360 and roughly sixty MCP tools, which is a real integration surface and a genuinely useful one, wrapped in a claim about the death of the browser that Salesforce itself does not act like it believes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The thing I would actually build against this week is detection, not capability. An implant voting across four providers means your model API traffic is now security telemetry, and almost nobody is logging it that way.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cisco Talos documented malware that lets four commercial AI models vote on its next move, and Opus 5.5 breaks four things your agent depends on.<\/p>\n","protected":false},"author":1,"featured_media":217,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"class_list":["post-218","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-news"],"_links":{"self":[{"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/posts\/218","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/comments?post=218"}],"version-history":[{"count":1,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/posts\/218\/revisions"}],"predecessor-version":[{"id":219,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/posts\/218\/revisions\/219"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/media\/217"}],"wp:attachment":[{"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/media?parent=218"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/categories?post=218"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/tags?post=218"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}