Cisco Talos develops CAIRN framework to detect AI-integrated malware

1 day ago 1



Cybercriminals are using the same AI coding assistants that developers love, tools like Claude Code, Codex, Cursor, and Gemini, to build functional malware. And according to Cisco Talos, they’re not even trying that hard to get around safety guardrails. Cisco’s threat intelligence division published research in August 2026 documenting how attackers exploit AI chatbots to develop hacking infrastructure. The most notable finding wasn’t some clever new jailbreak technique. It was how unnecessary clever techniques turned out to be. The fragmentation trick The primary method Talos observed is almost comically simple: task fragmentation. Attackers break malicious requests into smaller, innocuous-sounding pieces spread across multiple sessions and files. Each individual prompt looks harmless. The assembled result is a working DDoS tool or bulk-mail attack system. What makes this particularly concerning is the absence of sophisticated evasion tactics. Talos noted that attackers in the observed cases didn’t need advanced encoding or elaborate prompt engineering to get results. The existing guardrails on major AI platforms simply weren’t designed to catch intent distributed across separate i...

Read Entire Article