⌁AI·CYBER·BRIEF▌

#Credential Theft

AI Threats11 min read

The first supply-chain worm built for the AI memory layer — and why it skipped the install hook

The sckit worm reached npm and PyPI through MemTensor's release pipeline. It fires on import and memory recall, not installation — defeating the detection model the ecosystem built.

AnalysissckitMemTensor
AI Threats10 min read

CLOSEDQUORUM: malware that asks four AI models what to do next — and nobody has seen it used

Cisco Talos documented a Windows implant that replaces its command-and-control server with a vote among four commercial LLMs. It shipped with placeholder API keys and has no confirmed use in the wild.

AnalysisCisco TalosCLOSEDQUORUM
AI Threats12 min read

Carbonato: the Docker botnet whose AI agent is told to steal API keys before SSH credentials

ThreatDown documented a commodity Docker botnet that installs an off-the-shelf AI agent and ranks AI provider keys as loot #1 — above SSH credentials, tokens and databases.

AnalysisAgentic AICarbonato