Cybercriminals Use Task Fragmentation to Build Malware with AI Assistants
Cybercriminals are exploiting AI coding assistants to build functional malware, according to Cisco Talos' recent research. The threat intelligence division observed attackers using tools like Claude Code, Codex, Cursor, and Gemini to develop hacking infrastructure.
The primary method Talos noted is task fragmentation, where malicious requests are broken into smaller, innocuous-sounding pieces spread across multiple sessions and files. This technique doesn't require advanced encoding or elaborate prompt engineering, making it a concerning trend in AI-assisted attacks.
Cisco's Integrated AI Security and Safety Framework, released in December 2025 and updated in September 2026, aims to address the evolving threat landscape around AI-assisted attacks. The framework establishes a taxonomy for AI-related threats and covers categories like goal hijacking, jailbreaks, and failures associated with agentic autonomy.