Researchers uncover malware that uses AI to choose its next move Cisco Talos researchers released CAIRN, an open-source framework that classifies and analyzes AI-driven malware using only file metadata, without downloading or executing the malicious code. CAIRN Explorer links malware binaries through metadata attributes including submitter, import hash, domain, and AI provider, according to Cisco Talos. To help security practitioners catch malware that leans on AI, researchers from Cisco Talos shared an open-source framework that they hope will be used to classify and analyze the threat. The tool, called CAIRN, works entirely from metadata pulled off files. No downloading the malware, no running it. CAIRN explorer connects malware binaries by metadata attributes like submitter, import hash, domain or AI provider Source: Cisco Talos How CAIRN hunts Researchers look for what Talos … More https://www.helpnetsecurity.com/2026/09/22/cairn-open-source-framework-ai-malware-closedquorum/ The post Researchers uncover malware that uses AI to choose its next move https://www.helpnetsecurity.com/2026/09/22/cairn-open-source-framework-ai-malware-closedquorum/ appeared first on Help Net Security https://www.helpnetsecurity.com .