Malware That Lets Four Models Vote (09/22/2026)
- › ClosedQuorum asks four commercial AI providers what to do next and executes whichever action wins the vote, with no operator in the loop.
- › The public build ships dummy API keys and dead webhooks, so this is early tooling rather than mature offensive infrastructure.
- › Check Point is warning of a management server zero-day already exploited in targeted attacks, five days after a separate patched flaw.
- › Microsoft took down EvilTokens after it compromised 12,000 accounts, and UK police arrested two suspects.
- › A CVSS 10.0 flaw in VeloCloud Orchestrator is under active exploitation in certificate-based deployments.
Cisco Talos published something today worth reading in full, which is an implant that hands its tactical decisions to a panel of commercial AI models and does whatever the majority says. The build they analyzed is experimental rather than operational, and the design is the part that matters. Alongside that, Check Point has a management server zero-day already being used in targeted attacks, and Microsoft dismantled a phishing service that had worked through 12,000 accounts.
Top 5 Critical Security Alerts
1. ClosedQuorum Delegates Its Next Move to Four AI Models
Talos analyzed a 16.4MB Windows implant written in Go that queries up to four commercial providers, DeepSeek, Qwen, Mistral, and Google Gemini, and executes whichever action wins a plurality vote among them, with DeepSeek breaking ties. Responses are constrained to a typed schema offering steal, inject, persist, and move, and the implant carries LSASS dumping, browser credential theft across Chrome, Edge, and Firefox, and crypto wallet extraction from MetaMask and Exodus, per Cisco Talos and The Register. The public distribution build contains dummy API keys and non-functional webhooks, which puts it closer to proof of concept than to mature tooling.
Operator Note: The detection consequence is what to take from this. An implant deciding its own next action has no fixed playbook to signature, so the durable tells are the outbound calls to model providers and the credential access itself.
2. Check Point Management Server Zero-Day Under Targeted Attack
Check Point is warning that a zero-day in its management server is already being exploited in targeted attacks, per The Hacker News and BleepingComputer. This lands five days after the separate unauthenticated root flaw the vendor patched on September 17, so a team that patched last week is not covered for this one.
Operator Note: Two management server flaws in five days is a pattern rather than a coincidence, and the management plane is where an attacker gets to rewrite policy instead of evading it.
3. Microsoft Dismantles EvilTokens After 12,000 Account Compromises
Microsoft disrupted the EvilTokens device code phishing service, seizing 50 websites tied to the operation after it compromised roughly 12,000 accounts, and UK police arrested two suspects, according to BleepingComputer and The Register. Microsoft published its own technical breakdown of how device code phishing works.
4. VeloCloud Orchestrator Flaw at CVSS 10.0 Actively Exploited
A maximum severity flaw in VeloCloud Orchestrator is under active exploitation in certificate-based deployments, per The Hacker News. Orchestration platforms for wide area networking sit in the same awkward category as the workflow engines we covered on Sunday, holding credentials for everything they manage while rarely appearing in a patch cycle anybody owns.
5. Zyxel and Veeam Under Exploitation, With a Federal Deadline Attached
Zyxel and Veeam flaws are being exploited for command execution and SYSTEM level access, per The Hacker News, and CISA has ordered federal agencies to patch the Zyxel flaw by Thursday, according to BleepingComputer. Separately, Chinese actors are chaining WordPress and Zyxel flaws to steal government data.
Additional Security Alerts
Threat Intelligence
- Talos opens a tracking project for AI-integrated malware: CAIRN is an open-source research toolkit for monitoring malware that incorporates model APIs, and it is how ClosedQuorum was found. Cisco Talos
- Shai-Hulud reached CrowdSec’s GitHub data: The campaign that took roughly 170 private repositories from the security vendor is now attributed to Shai-Hulud. Dark Reading
- ShinyHunters claims an FBI breach through a PeopleSoft zero-day: The group says it holds data on FBI employees and applicants, which follows its takeover of Clop’s leak site two days ago. BleepingComputer
Security Breaches & Incidents
- Stolen passwords are exposing US water providers: Credentials for water utility systems are circulating, which puts operational technology in the hands of anybody willing to try them. TechCrunch
Cloud & Network Security
- Linux kernel flaw gives ARM64 KVM guests host memory access: A guest virtual machine can read and write host memory, which removes the boundary the hypervisor exists to provide. The Hacker News
- Rogue external MFA providers can harvest passwords: A malicious external multi-factor authentication provider can capture the password during the login it was meant to protect. BleepingComputer
- D-Link discloses a maximum severity zero-day in DIR-822A routers: Another end-of-life consumer router with a critical flaw and a limited path to a fix. BleepingComputer
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.