Ukraine's SSSCIP says Russian hackers are going after military and government phones, using hacked news and government sites to push the DarkSword iPhone kit. Because the kit needs little or no action from the victim, the defense falls on the phone's own software and how current it is.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence55
Cisco Talos found a 16.4MB Go implant that asks DeepSeek, Qwen, Mistral and Gemini what to do next and acts on the winning vote, treating the providers themselves as its C2 infrastructure. Talos has no confirmation it was ever deployed.
Perspective Coverage
7 publishers
- Builder
- Builder 28%
- Operator
- Operator 66%
- Investor
- Investor 6%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+30
- Incentives45
- Confidence62
Access Now says helpline requests ran 30% to 40% above the usual post-notification surge, a record. Among the recipients: a Ukrainian soldier who assumed the alert was a scam.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+25
- Incentives35
- Confidence60
ESET found the bait comment in a loader for MATCHBOIL, malware it ties exclusively to the Russia-aligned group that feeds targets to Sandworm. The trick works because a model that refuses to read a file returns no verdict at all.
Reality
- Evidence55
- Adoption20
- Hype gap+25
- Incentives40
- Confidence60
OpenAI is giving Ukraine's government its Daybreak cyber defence system and GPT-5.6 Sol for nothing. The only figure published alongside the deal is CERT-UA's count of nearly 6,000 attacks in 2025.
Reality
- Evidence44
- Adoption30
- Hype gap+28
- Incentives72
- Confidence52
Daybreak identifies weaknesses in digital systems and helps develop fixes. CERT-UA counted nearly 6,000 attacks in 2025. The free access extends a pattern OpenAI already runs with European firms and UK banks.
Reality
- Evidence52
- Adoption28
- Hype gap+18
- Incentives74
- Confidence55
Cisco Talos released its CAIRN framework on September 22nd to hunt prompts, provider endpoints and API-key prefixes in malware metadata. Its first case study polls four commercial models and runs the winner.
Reality
- Evidence58
- Adoption18
- Hype gap+10
- Incentives60
- Confidence55
Cisco Talos has open-sourced CAIRN, a framework that tags malware by the traces its AI calls leave in metadata. The first sample it surfaced polls DeepSeek, Qwen, Mistral and Gemini for orders and decides for itself.
Reality
- Evidence55
- Adoption18
- Hype gap+26
- Incentives62
- Confidence58