First reported · updated · 4 reports air.security
Lead dispatch
First reported · updated · 5 reports talosintelligence.com
The Closed Quorum: Inside the first reported autonomous AI C2 implant
Cisco Talos documented CLOSEDQUORUM, a Windows implant it describes as the first publicly reported autonomous AI command-and-control (C2) malware, discovered via its CAIRN project. The binary delegates its next-action decisions to a quorum of up to four commercial LLMs (DeepSeek, Qwen, Mistral, and Google Gemini) queried in sequence, executing their chosen actions to harvest credentials and crypto wallets without a human operator or dedicated C2 server; Talos has no confirmation of in-the-wild deployment but linked the developer to carding forum postings.autonomous-agent · ai-c2 · malware · data-exfiltration · tool-abuse
llm · ai-agents · windows
The wire · latest
First reported · updated · 5 reports forever.security
BragJack: How We Hijacked 5 Of The World's Most Popular Browsers Using Their Built-In AI Assistants
Researchers at Forever Security ("BragJack") and Zenity Labs ("PleaseFix") disclosed a new class of zero-click agent-hijacking flaws affecting built-in AI assistants in Chrome (Gemini), Perplexity Comet, Microsoft Edge, Opera Neon, and Claude in Chrome, earning tens of thousands in bounties and CVEs including CVE-2026-0628 and CVE-2026-55945. The root design flaw is that agentic browsers combine trusted and untrusted content from multiple origins, breaking same-origin isolation and letting hidden malicious instructions weaponize the agent to access local files, camera/microphone, browser profiles, history, and connected accounts. Separately, Manifold Security reported two Claude for Chrome extension bugs (a missing event.isTrusted check and a ?skipPermissions=true privileged-init weakness) that remain unpatched in v1.0.80, enabling any browser extension to trigger Claude to read Gmail, Docs, and Calendar. Details →First reported calif.io
WeChat's 1.4 Billion Users Faced a Dangerous Security Flaw. AI Helped Turn It Into a Self-Spreading Worm.
Researchers at Calif, a Palo Alto cybersecurity firm, demonstrated WeWorm, a proof-of-concept zero-click worm that exploited a flaw in WeChat's voice-calling system to take over accounts across iOS and Android without any user interaction, and used compromised contacts to spread to their address books. The team said it built the tool in about a week with help from open-source and leading U.S. AI models; Tencent confirmed and fixed the flaw by August 28 and said no users were affected. Details →First reported · updated · 2 reports calcalistech.com
Israeli researchers uncover zero-click attacks targeting AI browsers | Ctech
Israeli researchers demonstrated zero-click attacks against AI-powered browsers, reportedly hijacking agentic assistants like Anthropic's Claude and OpenAI's ChatGPT Atlas via malicious content embedded in emails and X posts. The attacks use indirect prompt injection that executes without any user interaction once the AI browser processes the poisoned content. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector