CLOSEDQUORUM, the malware that asks four AI models what to do next
2026-09-24T08:51:36Z•d410d74c432e2bb8a65fba0f94b666234a321dff9e8dc34d82ac255bdde1e022
CVE-2026-85102CVE-2026-87902CVE-2026-93616CVE-2026-94127AI-assisted malwareCISA KEVCheck PointF5 BIG-IP APMMicrosoft DefenderVeeam AgentWordPressactively exploited vulnerabilitiesdata breachdevice-code phishinginfostealerlocal file inclusionmalwarepath traversalphishing-as-a-serviceprivilege escalationremote code executionsecurity-tool disablingsigned driver abusezero-day
What happened
SecurityAffairs reports multiple major cybersecurity developments, including actively exploited zero-days in F5 BIG-IP APM and Check Point Security Management Server, a critical WordPress file-inclusion flaw potentially enabling remote code execution, phishing-as-a-service activity compromising over 12,000 inboxes, and malware campaigns using signed drivers to disable security software. Additional reports cover alleged breaches, public proof-of-concept exploits, and emerging AI-assisted malware.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- d410d74c432e2bb8a65fba0f94b666234a321dff9e8dc34d82ac255bdde1e022
- Enrichment time
- 2026-09-24T08:51:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.