Making sure the checks get printed
Cisco Talos CAIRN research reveals malware authors embedding natural-language prompt-injection instructions in binaries to evade AI-assisted analysis, succeeding ~35% of the time.
Cisco Talos discloses new CAIRN research on 'A3: AI-Analysis Evasion,' where malware authors embed natural-language instructions in code—from simple ignore comments to 'template spraying' targeting LLMs—to manipulate AI-assisted analysis, steering verdicts roughly 35% of the time. The MANTLEMAZE family pairs these AI deceptions with abusing vulnerable drivers to disable EDR from kernel space. The newsletter also rounds up the week's headlines: Citrix NetScaler CVE-2026-88779 (memory overflow DoS, more zero-day reports), an 8 million-record breach of Denmark's CPR database via a company's lawful access, Warlock ransomware hitting four Spanish/Portuguese victims, and a US Senate healthcare cybersecurity bill after the 190-million-record Change Healthcare breach.
- Talos CAIRN dubs trend 'A3: AI-Analysis Evasion': natural-language instructions embedded in malware to mislead AI analyzers.
- Prompt-injection tricks steer AI verdicts ~35% of the time; adoption spans all malware sophistication levels.
- MANTLEMAZE pairs AI deception with vulnerable-driver abuse to disable EDR from kernel space.
- Defenders should flag imperative text aimed at analysis systems and treat sample text as evidence, not directives.
- Weekly roundup: Citrix CVE-2026-88779 DoS zero-day, 8M-record Danish CPR breach, Warlock ransomware in Iberia.
Vulnerabilities mentionedAll →
- CVE-2026-887798.7<1%Unauthenticated denial of service in NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-88779 | Unauthenticated denial of service in NetScaler ADC and Gateway CVE-2026-88779 is a high-severity vulnerability (CVSS 4.0 base score 8.7) in Citrix NetScaler ADC and NetScaler Gateway. CVSS metrics indicate it can be triggered remotely over the network with low complexity, no privileges, and no user interaction; the advisory text does not name a specific bug class or request path. Impact is limited to high loss of availability on the vulnerable appliance, with no confidentiality or integrity impact scored for the device or for subsequent systems, which is consistent with denial of service. Affected products are NetScaler ADC before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282, and NetScaler Gateway before 14.1-73.41 and before 13.1-64.28. It is not listed in CISA KEV, and no public proof-of-concept is known. |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| md5 | 207d9d891ac756b2bfad88aba5682c65 | caf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f MD5: 207d9d891ac756b2bfad88aba5682c65 Talos Rep: https://talosintelligence.com/talos_file_reputat |
| md5 | 2915b3f8b703eb744fc54c81f4a9c67f | d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat |
| md5 | 38de5b216c33833af710e88f7f64fc98 | bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat |
| md5 | 63f3351cfdf618bec6045f60203e7978 | e6c76c34f655ac0477a4cd930f2aa55e658c8e312ff81aac9a741f MD5: 63f3351cfdf618bec6045f60203e7978 Talos Rep: https://talosintelligence.com/talos_file_reputat |
| md5 | f1fe671bcefd4630e5ed8b87c9283534 | 24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681 MD5: f1fe671bcefd4630e5ed8b87c9283534 Talos Rep: https://talosintelligence.com/talos_file_reputat |
| sha256 | 58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681 |
Full article1,227 words · extracted from blog.talosintelligence.com · click to collapse
Thursday, October 8, 2026 14:00
Welcome to this week’s edition of the Threat Source newsletter.
My name is Pierre Cadieux, and I’ll be helping contribute to these newsletters. A little about me: I’ve been working in the cybersecurity industry in many roles over the past 20+ years, first focusing on endpoint security, policies, and firewalls, then moving to risk management and compliance, disaster recovery, and investigations. I spent about 15 years as a consultant working across many well-known consultancy firms and eventually moved to Cisco where I spent time doing security operations center (SOC) design and assessments as well as segmentation before moving to the Talos IR team. I spent many years there, first as an Incident Commander and then a manager of our excellent team of global IR consultants and investigators. My current role is with the Talos Threat Intelligence and Interdiction team, where I’m focused on intelligence efficacy — how we can do better with the data we have, how we can get more data, and what our customers want from our intelligence products.
Since it’s Cybersecurity Awareness Month, I wanted to take a few minutes to collectively thank all of the defenders out there for the hard work you do each day. The work you do may not always be visible, but it matters.
I remember one job I had many years ago when I was in charge of security for a financial institution. I spent time learning each of the business processes that we had so I could understand each of the moving parts, what was essential, and what was on the horizon for change. I even spent a couple days meeting with the folks who handled printing. Yeah, printing — but not reports or internal documents. These were the people that created the checks that our institution used to pay other institutions, and more importantly (to me) our customers.
I recall there being many out-of-patch compliance boxes in this area of the company, so I, being the diligent Director, decided to find out why. It turns out the software being used to print these business essential checks would not run on the current operating systems, and the physical printer cards used to connect to these non-network printers also required older hardware ports. As one of the people I interviewed said, “We don’t want to be the reason someone’s grandma doesn’t get her check and can’t go to the grocery store.”
There were (at the time) no other alternatives that we could deploy, and the environment had zero tolerance for downtime. The solution I proposed was to isolate these devices into their own network, which blocked access to and from the internet for these devices, and also reduced the likelihood that these devices would be identified during an adversary’s internal reconnaissance or mapping. It didn’t patch the vulnerable devices, but it went a long way to reducing the likelihood of a bad thing happening to these devices due to their out-of-date OS and software.
This story is especially appropriate today, as we face ever-increasing numbers of vulnerabilities announced by software vendors, and can only expect this volume to continue to increase. Do what you can to make sure the checks still get printed, while managing your risks intentionally.
The one big thing
Cisco Talos is disclosing new findings from our CAIRN research that show malware authors are embedding natural-language instructions into their code to evade AI-assisted analysis. We classify this growing trend as "A3: AI-Analysis Evasion." Over the past 18 months, we've tracked techniques ranging from simple comments telling an AI to ignore a file, to advanced "template spraying" designed to trick specific large language models (LLMs).
Why do I care?
Attackers expect AI to be in your analysis pipeline, and they’re developing cheap methods to manipulate those systems. While we found these prompt-injection techniques only steer the AI's verdict in the attacker's favor about 35 percent of the time, they are being adopted across all levels of malware sophistication. A3 families like MANTLEMAZE also pair these AI deceptions with serious underlying threats, such as abusing vulnerable drivers to disable EDR from kernel space.
So now what?
Because these evasion instructions must be written in plaintext, defenders have a highly stable detection surface to monitor. Security teams should flag imperative language addressed to analysis systems within binaries as a suspicious signal. Most importantly, anyone building or using AI-assisted pipelines must ensure that text extracted from a sample is strictly treated as evidence, never as a system directive. Read the full blog for more information on these techniques and a list of sample hashes.
Top security headlines of the week
Citrix NetScaler security snafus get even worse amid more zero-day reports
This latest vulnerability, tracked as CVE-2026-88779, is a memory overflow bug that leads to denial of service attacks. (The Register)
Hackers steal 8 million citizens’ records from Danish government database
The Danish government would not say who is behind the breach, which happened in September but was discovered on October 2. However, it said the unauthorized access was obtained by “abusing a Danish company’s lawful access to search for information in the CPR system.” (TechCrunch)
Google narrows open-source bug bounty amid wave of invalid automated reports
Google has temporarily closed its Open Source Software Vulnerability Reward Program (OSS VRP) to product vulnerability submissions. According to Google, it has no impact on the program’s supply chain reports or on any pending reports. (SecurityWeek)
Warlock ransomware hits large Spanish, Portuguese orgs
In the last two months, researchers observed Warlock attacks against four victims: a water utility, a telecommunications provider, a regional government body, and a university. (Dark Reading)
U.S. Senate passes health care cybersecurity bill after 190 million impacted by Change Healthcare breach
The Health Care Cybersecurity and Resiliency Act of 2026 was passed by unanimous consent last week, potentially expanding federal cyber requirements for health care organizations. (The Record)
Can’t get enough Talos?
One breach, please, and make no mistakes
The cybersecurity community has seen examples of autonomous agents, built inside AI labs, attacking public infrastructure. How you prepare for agentic threats is what makes the difference during real incidents.
Talos Takes: Honey, I Trapped the Adversary
It’s time to start having fun and messing with your attackers. For Cybersecurity Awareness Month, Martin Lee joins Amy to discuss the fine art of making life on your network a complete nightmare for adversaries.
The Fine Art of Frustrating the Adversary
What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier, from deception and behavioral detection to breaking attack dependencies.
Upcoming events where you can find Talos
- VB (Oct. 14 – 16) Seville, Spain
- CAMLIS (Oct. 21 – 23) Arlington, VA
- SecurityOnion Conference (Oct. 23) Augusta, GA
- BsidesAugusta (Oct. 24) Augusta, GA
- SAINTCON (Oct. 26 – 30) Provo, UT
Most prevalent malware files from Talos telemetry over the past week
SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
MD5: 2915b3f8b703eb744fc54c81f4a9c67f
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
Example Filename: sample.exe
Detection Name: W32.9F1F11A708-100.SBX.TG
SHA256: fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f
MD5: 207d9d891ac756b2bfad88aba5682c65
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f
Example Filename: sample.exe
Detection Name: W32.FED979F93B-95.SBX.TG
SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
MD5: 38de5b216c33833af710e88f7f64fc98
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
Example Filename: SECOH-QAD.exe
Detection Name: W32.9896A6FCB9-95.SBX.TG
SHA256: 73ac1bbfaee6c76c34f655ac0477a4cd930f2aa55e658c8e312ff81aac9a741f
MD5: 63f3351cfdf618bec6045f60203e7978
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=73ac1bbfaee6c76c34f655ac0477a4cd930f2aa55e658c8e312ff81aac9a741f
Example Filename: f_003914.exe
Detection Name: W32.PUP:PulseBrowser.29kh.in12.Talos
SHA256: 58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681
MD5: f1fe671bcefd4630e5ed8b87c9283534
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681
Example Filename: KMSAuto Net.exe
Detection Name: W32.58D6FEC4BA-95.SBX.TG