Cisco Talos read CLOSEDQUORUM statically: a Go binary that polls DeepSeek, Qwen, Mistral and Gemini before it touches LSASS. The distributed sample has dummy keys. One answering provider can carry the vote.
Reality
- Evidence58
- Adoption8
- Hype gap+25
- Incentives60
- Confidence55
Microsoft's Defender Experts date the Contagious Interview campaign to December 2022. Its payload lands at the one hiring stage where a candidate is expected to clone and run a stranger's code. The same team tells employers to give staff a non-persistent VM for coding tests.
Reality
- Evidence64
- Adoption35
- Hype gap+8
- Incentives58
- Confidence62
Microsoft's September 17 post pins three current campaigns on excessive permissions, open authentication flows and sanctioned admin tooling, and says the change AI brought is the speed at which those combine.
Reality
- Evidence42
- Adoption31
- Hype gap+26
- Incentives84
- Confidence58
Kaspersky says the trojanized torrents come from itorrents.org, the file archive many trackers pull from, and that the archive was still returning substituted files when the report went out. Organizations are among the several hundred victims.
Reality
- Evidence62
- Adoption52
- Hype gap+6
- Incentives58
- Confidence55
CrowdStrike's 2026 Global Threat Report carries both numbers, and the gap between them decides whether a control has to run without a person or can wait for someone on shift to look.
Reality
- Evidence46
- Adoption18
- Hype gap+42
- Incentives82
- Confidence52
The 154-page threat report says actors beat the company's region blocks and hid the purpose of their research, so Anthropic banned accounts and published the pattern with every country and institution removed.
Perspective Coverage
7 publishers
- Builder
- Builder 35%
- Operator
- Operator 36%
- Investor
- Investor 29%
Reality
- Evidence54
- Adoption55
- Hype gap+34
- Incentives71
- Confidence68
Google's Threat Intelligence Group says a suspected financially motivated actor assembled the rig from an AI coding chatbot and preconfigured Markdown files, then ran it inside a compromised cloud tenant.
Reality
- Evidence34
- Adoption22
- Hype gap+12
- Incentives62
- Confidence40
Anthropic's December-to-August threat report says none of the intrusions it disrupted used a novel technique. Stolen credentials and unpatched edge devices opened the doors, at machine speed, for single operators.
Reality
- Evidence52
- Adoption52
- Hype gap+22
- Incentives80
- Confidence50
Google Threat Intelligence Group's September 8 report puts a financially motivated actor, UNC6780, inside PyPI, npm and Docker Hub, publishing under stolen maintainer automation and reselling the AI tool credentials it collects afterwards.
Reality
- Evidence54
- Adoption45
- Hype gap+22
- Incentives64
- Confidence56
Mandiant traced the Q2 2026 campaign to an AI coding chatbot, one prompt and a set of agent instructions that ran the scanning pipeline, fixed its own errors and rotated IPs with nobody at the keyboard.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 57%
- Investor
- Investor 13%
Reality
- Evidence58
- Adoption62
- Hype gap+24
- Incentives70
- Confidence66
Comparitech's half-year tally shows government ransomware growing again, with the newest crew on the board, The Gentlemen, out-filing Qilin and spreading its targeting well beyond the United States.
Publishers:comparitech.com
Reality
- Evidence50
- Adoption60
- Hype gap+20
- Incentives62
- Confidence55
The interesting part of the SPECTRE report is not the implant. It is an adversary using AI to diagnose failed exploit attempts and generate retry steps against a list of about 170,000 URLs.
Reality
- Evidence42
- Adoption30
- Hype gap+32
- Incentives55
- Confidence45
Cisco Talos says UAT-10147, a Chinese-speaking crew that monetizes access through search ranking fraud, now runs a cross-platform implant with kernel-level EDR bypass and a Linux rootkit.
Reality
- Evidence62
- Adoption34
- Hype gap+18
- Incentives66
- Confidence57
Hunt.io says over 14,530 cameras fell to three parallel vectors. Two are the operator's problem. The third, the vendor's own P2P relay, opens on a serial number alone.
Reality
- Evidence58
- Adoption66
- Hype gap+10
- Incentives55
- Confidence52
FortiGuard Labs says Evooo1Bot packs SOCKS5 relaying, credential sniffing, SSH spreading and 16 flood modes into one binary across 12 CPU architectures. The tunnel matters more than the flood.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+18
- Incentives58
- Confidence42