· artificial intelligence · 6 min read

AI and cloud briefing: malware lets AI models vote on its next move, Anthropic and OpenAI chase smaller data centres, and a critical F5 zero-day is under attack

Cisco Talos disclosed CLOSEDQUORUM, Windows malware that queries four AI models and lets them vote on its next move. Anthropic and OpenAI are both pursuing smaller, faster data centre deals while their gigawatt-scale campuses are still being built. And CISA has added a critical F5 BIG-IP zero-day, already under active attack, to its exploited vulnerabilities catalogue.

Cisco Talos disclosed CLOSEDQUORUM, Windows malware that queries four AI models and lets them vote on its next move. Anthropic and OpenAI are both pursuing smaller, faster data centre deals while their gigawatt-scale campuses are still being built. And CISA has added a critical F5 BIG-IP zero-day, already under active attack, to its exploited vulnerabilities catalogue.

Here is our latest round-up of what’s changing in AI and cloud for UK businesses, with links to the original sources so you can read further.

Lead story: malware discovered that lets four AI models vote on its next move

Cisco Talos researchers disclosed CLOSEDQUORUM on 22 September 2026, describing it as the first documented Windows malware that uses commercial AI models to decide its own actions, instead of relying on a human operator or fixed, hard-coded logic. Talos found it while testing CAIRN, a new tool it built specifically to detect AI-integrated malware. CLOSEDQUORUM sends basic details about the infected computer, its name, Windows version, and whether it is running with administrator rights, to up to four AI services in turn: DeepSeek, Qwen, Mistral and Google Gemini. Each model votes for one of four possible actions: stealing data (dumping Windows credentials from memory, taking saved passwords from Chrome, Edge and Firefox, and extracting cryptocurrency wallet data), injecting code into another running process, setting up ways to survive a reboot, or moving to another machine (this last option does not actually work in the copies Talos examined). Whichever action gets the most votes is carried out, and a tie is broken in favour of DeepSeek’s vote. Results and any stolen data are sent back to the attacker over a Discord webhook. Talos said the samples it examined were not fully working, because they contained placeholder API keys and Discord addresses rather than real ones, and it has not seen the malware operating end-to-end against a real target. More detail is available from Cisco Talos’s original write-up and The Hacker News’s coverage.

Cisco Talos disclosed CLOSEDQUORUM, malware that queries four AI models and lets them vote on its next move

Why this matters: this is not yet a working attack in the wild, but it shows criminal developers are actively experimenting with using commercial AI models as a decision-making engine inside malware, rather than only using AI to write phishing emails or code. If this design matures, attackers could change an infected machine’s behaviour just by changing a prompt, rather than pushing new malware code, which would make it harder to predict and detect. It is a good moment to check whether your security tools can flag unusual outbound traffic from ordinary business devices to AI provider APIs and platforms such as Discord.

Cloud and AI infrastructure: Anthropic and OpenAI chase smaller data centres while gigawatt sites are built

According to reporting first published by CNBC on 18 September 2026, both Anthropic and OpenAI are now pursuing smaller data centre deals, in the 20 to 30 megawatt range, to bring new computing capacity online faster while their much larger, gigawatt-scale campuses are still being built and connected to power grids. This sits alongside their headline-grabbing larger commitments: Anthropic has separately agreed deals for roughly 460 megawatts of capacity with Nscale in West Virginia, reported to be worth around $45 billion, 5 gigawatts of capacity from Amazon, and 5 gigawatts of next-generation TPU capacity from Google and Broadcom, while OpenAI has planned capacity of 3 gigawatts in Georgia and 8 gigawatts in Ohio. Both companies have also been scouting smaller sites in the UK and Nordic countries. Property firm JLL is cited as projecting that “inference” workloads, running an already-trained AI model to answer questions, as opposed to the separate, much larger job of training it, will grow from 9% of global data centre capacity in 2025 to 37% by 2030, and could overtake training as the biggest use of AI data centres by 2027. More detail is available from MarketScreener’s coverage of the CNBC report and Anthropic’s own announcement of its Google and Broadcom compute deal.

Anthropic and OpenAI are pursuing smaller, faster data centre deals alongside their gigawatt-scale campuses still under construction

Why this matters: the shift toward smaller, faster-to-build sites reflects a practical bottleneck, grid connections and planning permission take time regardless of how much money is available, and it signals that serving AI answers to real users is becoming a larger and more urgent workload than training new models. For UK businesses, this points to more regional AI infrastructure and potentially more competitive, more locally hosted AI services becoming available over the next few years, which is worth factoring into any longer-term cloud or AI procurement planning.

Cybersecurity: critical F5 BIG-IP zero-day is under active attack

F5 has released emergency fixes for CVE-2026-94127, a critical heap-based buffer overflow in BIG-IP Access Policy Manager (APM) when it is configured as an OAuth authorisation server, scoring 9.8 out of 10 on the CVSS 3.1 scale. The flaw affects BIG-IP APM versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3, and allows unauthenticated remote code execution. CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue on 22 September 2026, confirming it is already being actively exploited. F5 has published engineering hotfixes and, for organisations that cannot patch immediately, an iRule-based mitigation. The company has also advised customers to check for signs of compromise, including repeated OAuth authentication failures, unusual commands, and unexpected core files from BIG-IP’s traffic management microkernel, and to preserve evidence before applying the fix so any prior compromise can still be investigated. More detail is available from The Hacker News’s report and CISA’s Known Exploited Vulnerabilities catalogue.

F5 has issued emergency fixes for a critical, actively exploited zero-day in BIG-IP Access Policy Manager

Why this matters: BIG-IP APM is widely used by larger organisations to manage remote access and single sign-on, so a critical, unauthenticated, actively exploited flaw in it is a genuine emergency rather than routine patching. If your business or a third party you rely on runs F5 BIG-IP with APM configured for OAuth, this is worth checking against your patch records this week, and worth asking your IT provider or managed security partner to confirm directly rather than assuming it has already been handled.

The takeaway

Today’s stories share a common thread: attackers and defenders alike are adapting faster than most patch cycles and procurement plans are built for. Criminal developers are already testing AI models as a decision engine for malware, even though this particular example is not yet functional, while legitimate AI providers are redesigning their own infrastructure plans around how quickly they can bring inference capacity online. Meanwhile, a critical, actively exploited flaw in widely used access management software is a reminder that some patches genuinely cannot wait. We can help you work through what applies to your business. Get in touch.


AI Agent based research and content, AI can do mistake, please help us to improve.

Back to Blog