@nikks_techie Honestly question you should be asking is why there are two tools and getting different results? Also tools should be deterministic where possible. If this will be a shared behavior may be worth building into an MCP so future agents can get to the correct answer as well.
Same folks complaining about the internet and cloud computing are fighting AI. They are more vehement this go around because they are frightened. I get it, but good news is protecting generative AI is the same job we've been doing for years. A couple unique new knobs and dials. But good security applies super well to agents and generative AI.
EvilTokens industrialized AI-assisted BEC after device-code token theft.
Microsoft tracked the PhaaS kit from February 2026: lure → live device code on a fake page → victim completes real microsoft[.]com/devicelogin → attacker session gets the token.
Post-compromise, an AI assistant sifted the mailbox, mapped roles and payment paths, and drafted impersonation mail—linked to more than 12,000 compromised inboxes across over 10,000 organizations.
Monday control: block device code flow in Conditional Access except tightly scoped exceptions; on suspect token theft, revoke sign-in sessions (and temporarily disable if needed); alert on new inbox rules after anomalous device-code auth.
Source: Microsoft Threat Intelligence / Defender Experts / Security Research — “Unmasking EvilTokens: Getting to the root of device code phishing,” Microsoft Security Blog, Sept 22, 2026.
https://t.co/VXTg9cfhq6
Not unpopular, tend to agree, but it is interesting to see it be commercialized and more mainstreamed. And honestly the weird transformer/classifier hybrid does have some unique attributes. Sadly everything is hype right now. What was shocking was how fast laya came up afterwards.
Cisco Talos just documented CLOSEDQUORUM: a Windows implant that treats commercial LLMs as C2.
Up to four models — DeepSeek, Qwen, Mistral, Gemini — each vote on the next action. Plurality wins. Options are constrained to JSON: steal, inject, persist, move.
On “steal,” it runs LSASS dump, browser credential theft, and crypto-wallet extraction in one pass. Telemetry and loot go to Discord (AES-256-GCM).
The public build ships with dummy API keys, so Talos did not see a live end-to-end loop. Still the first publicly documented Windows implant that delegates tactical C2 to an LLM panel instead of an attacker-run server.
Detection angle from Talos: don’t block the AI domains. Watch for a process hitting several model APIs *and* LSASS / injection / WMI persistence.
https://t.co/qCmjHOlNIb
@PumpkinSecurity I think layla, jev, and those transformer/classifier hybrids will likely be bigger in the future as opposed to straight to frontier models.
AI got unusually good at coding because developers spent decades doing something most fields don’t: stating a concrete problem, then publishing a working solution next to it.
Stack Overflow, GitHub, blogs, talks. Problem → explanation → code, at massive scale.
Code is also structured and testable. That combination is rare.
So before you go hating on developers and saying they suck, please remember AI is likely great at code because of the corpus of knowledge they shared.