
Sembra che il mondo della cyber-sicurezza stia per fare i conti con un’ondata di malware guidato non da maledetti programmatori (anche se ci sono), ma da ‘mente di sciame’ artificiale. Cisco Talos, i cui ricercatori hanno sviluppato un framework open-source chiamato CAIRN (Cognitive Artifact Intelligence Research Network), è pronto a tracciare queste nuove bestie digitali. In pratica, CAIRN funge da detective iper-tecnologico che individua le ‘impronte digitali’ dell’AI all’interno del codice maligno. I ricercatori hanno già dimostrato l’efficacia del metodo. Un esempio lampante è CLOSEDQUORUM, un tipo di malware per Windows che, anziché seguire un singolo comando, si consulta in tempo reale con fino a quattro LLM (Large Language Models) – tipo DeepSeek, Qwen, Mistral e Google Gemini. L’idea è raggiungere un consenso per decidere il prossimo passo. Se un LLM va offline, non fa i capricci: pollera gli altri per trovare un accordo. Tutto questo avviene in un sistema totalmente autonomo, senza l’intervento umano. Un ricercatore di Cisco Talos ha notato che il panorama del malware potenziato dall’AI è molto più complesso e variegato di quanto i media o le segnalazioni pubbliche suggeriscano. Questo non è solo un giocattolo per la produttività; per gli aggressori, l’AI è diventata una vera e propria ‘arma operativa’ che permette di lanciare campagne su larga scala, colpendo più bersagli e diverse configurazioni di sistemi, trasformando il campo di battaglia digitale in qualcosa di pazzesco e inarrestabile.
🇬🇧 Summary in English
Looks like the cybersecurity world is bracing for a wave of malware guided not by sketchy programmers (though they still exist), but by an artificial ‘swarm intelligence.’ Cisco Talos researchers, who developed an open-source framework called CAIRN (Cognitive Artifact Intelligence Research Network), are ready to track these new digital beasts. Essentially, CAIRN acts like a hyper-tech detective, identifying the ‘digital fingerprints’ of AI embedded within malicious code. The researchers have already demonstrated the framework’s effectiveness. A prime example is CLOSEDQUORUM, a Windows malware that, instead of taking a single command, polls up to four LLMs—like DeepSeek, Qwen, Mistral, and Google Gemini—to reach a consensus on its next move. If one LLM goes offline, it doesn’t panic: it checks the others to find an agreement. This entire process happens in a totally autonomous system, requiring zero human input. A Cisco Talos researcher noted that the landscape of AI-powered malware is far more complex and diverse than what has been publicly reported. This isn’t just a productivity booster; for attackers, AI has become a genuine ‘operational weapon.’ It allows them to launch large-scale campaigns, hit more targets, and manage diverse system configurations, making the digital battlefield insanely complex and hard to contain.
Leggi l’articolo originale su Wired EN →
Fonte: Wired EN | Argomento: Cybersecurity
#tecnologia #innovazione #technews