By: Network-Switch.com | September 28, 2026
- 1. Quick Summary
- 2. Cisco-Omdia Research Shows AgenticOps Moving Into Production
- 3. Cisco Talos Documents Autonomous AI Command-and-Control Malware
- 4. Notre Dame Standardizes Its Campus Network on Cisco Catalyst
- 5. Cisco Demonstrates Heterogeneous NVIDIA and AMD AI Inference Over Ethernet
- 6. Cisco and VAST Extend the Confidential AI Architecture
- 7. Cisco Expands LLM Security Testing to Image and Audio
- 8. Network-Switch.com Observation
- 9. Frequently asked questions (FAQs)
- 10. Sources
Quick Summary
Cisco's September 20-27 updates focused on how AI is changing network operations, infrastructure design and security. New Cisco-Omdia research shows rapid adoption of AgenticOps, while Cisco Talos documented an autonomous AI-driven malware architecture. At the infrastructure layer, Cisco demonstrated heterogeneous NVIDIA and AMD inference over a Silicon One-based Ethernet fabric, supported a major Notre Dame campus refresh, expanded confidential AI work with VAST, and added image and audio attack testing to its LLM Security Leaderboard.
Cisco-Omdia Research Shows AgenticOps Moving Into Production
On September 23, Cisco released Omdia research based on a global survey of 1,000 IT and network operations leaders at organizations with at least 500 employees. Cisco reported that 95% said their existing non-agentic AIOps tools fall short in at least one significant area, while 51% already use agentic AI systems that take action in production.
The study also found that 84% expect to reach an AI-led operating model within 12 months. Cisco estimated that the average organization processes roughly 4,100 monitoring alerts and events per day, with about half related to the network. Network World independently highlighted the estimate that manually clearing that volume would require roughly 100 specialists.
Network-Switch.com view: AgenticOps should not be treated as a substitute for network architecture. Before an agent can change routing, wireless, firewall or access policy, enterprises should define approval boundaries, rollback procedures, audit logging and the operational data sources the agent is allowed to trust.
Cisco Talos Documents Autonomous AI Command-and-Control Malware
On September 22, Cisco Talos released CAIRN, an open-source toolkit for tracking AI-integrated malware, and published an analysis of CLOSEDQUORUM. Talos describes CLOSEDQUORUM as the first publicly documented Windows implant it has seen that delegates tactical command-and-control decisions to a panel of commercial large language models.
The implant can query multiple LLM providers and select among predefined actions such as credential theft, process injection and persistence. Talos emphasized that it has not confirmed in-the-wild deployment, and the public sample contains placeholder API credentials rather than a fully operational configuration. Wired independently covered the research.
Network-Switch.com view: The defensive implication is behavioral. Blocking AI-provider domains alone would create false positives because legitimate applications use the same services. Network and security teams should correlate unusual AI API traffic with endpoint behavior, identity events, credential access and exfiltration patterns.
Notre Dame Standardizes Its Campus Network on Cisco Catalyst
On September 22, Cisco and Notre Dame Athletics announced a multi-year partnership to modernize the University of Notre Dame's campus network. Notre Dame said the project is designed to remove technical debt and build a common multi-gigabit infrastructure for academic, administrative and AI-driven workloads.
The South Bend campus is being standardized on nearly 1,000 Cisco Catalyst 9300X switches. Cisco Catalyst Center will provide automation, assurance and zero-touch deployment, while ThousandEyes will extend visibility beyond networks directly owned by the university.
Network-Switch.com view: Large campus refreshes are not only switch-replacement projects. A deployment approaching 1,000 access switches requires accurate port counts, PoE planning, uplink and optical design, software standardization, staging and rollback procedures, and a management architecture that can maintain consistent configuration across the site.
Cisco Demonstrates Heterogeneous NVIDIA and AMD AI Inference Over Ethernet
Cisco published details on September 21 of its MLPerf Inference v6.1 submission using NVIDIA H200 and AMD Instinct MI350X accelerators in the same distributed inference service. The systems were connected through a Cisco Silicon One G200-based Ethernet fabric.
For the GPT-OSS 120B server workload, Cisco used the NVIDIA H200 group for prefill and the AMD MI350X group for decode. MLCommons independently described Cisco's submission as the benchmark's first cross-vendor heterogeneous accelerator deployment, combining eight NVIDIA H200 and eight AMD Instinct MI350X GPUs in one inference pool.
Network-Switch.com view: AI infrastructure is rarely refreshed all at once. If heterogeneous accelerator pools can be used efficiently, enterprises gain more flexibility to reuse installed compute. The network becomes critical because latency, RDMA behavior, congestion management and fabric consistency determine whether disaggregated inference remains practical.
Cisco and VAST Extend the Confidential AI Architecture
On September 24, Cisco detailed its work with VAST Data on confidential AI for organizations that need to use sensitive data without exposing either enterprise information or proprietary model weights during inference. The architecture builds on Cisco Secure AI Factory with NVIDIA and VAST DataEnclave.
VAST describes DataEnclave as a confidential AI runtime inside VAST DataEngine using NVIDIA Confidential Computing, hardware-isolated execution, cryptographic attestation and independent key control. VAST says the capability is in preview and is planned to ship in Q1 2027 through VAST and participating OEM partners including Cisco and Supermicro.
Network-Switch.com view: Confidential AI adds another layer to AI infrastructure design. Buyers need to validate trusted-execution support, GPU and server compatibility, key-management integration, east-west network segmentation, storage paths and whether the full solution remains supported in sovereign or air-gapped environments.
Cisco Expands LLM Security Testing to Image and Audio
On September 24, Cisco expanded its LLM Security Leaderboard beyond text-only testing to include image and audio attacks. Cisco said the update adds 55 image-model entries and 14 audio-model entries, allowing organizations to compare model resistance across the input surfaces their agents actually use.
The change matters because an AI agent can encounter malicious instructions in screenshots, diagrams, advertisements or audio rather than conventional text prompts. Cisco also connected open-weight leaderboard entries to its AI Supply Chain Provenance Explorer so security teams can review both model behavior and model lineage.
Network-Switch.com view: AI security testing should match the deployment. A text-only internal assistant and a multimodal agent with browser, camera or voice access do not have the same attack surface. Model selection should therefore consider the exact modalities, tools and network permissions exposed in production.
Network-Switch.com Observation
The common theme this week is that AI is becoming a network operations and infrastructure problem, not only an application problem. Autonomous network agents need trusted telemetry and strong change controls; AI clusters need predictable Ethernet fabrics; confidential AI needs secure data paths; and AI-enabled attacks create new traffic patterns that defenders must recognize.
For enterprise buyers, the practical response is to review the full system rather than isolated devices. Switching capacity, optics, management platforms, telemetry, security policy, identity, compute architecture and software lifecycle should be validated together before deployment.
Frequently asked questions (FAQs)
What did Cisco and Omdia find about AgenticOps in enterprise networks?
Cisco and Omdia surveyed 1,000 IT and network operations leaders. Cisco reported that 95% said existing non-agentic AIOps tools fall short in at least one major area, 51% already use agentic AI systems that act in production, and 84% expect to reach an AI-led operating model within 12 months.
What is CLOSEDQUORUM and what did Cisco Talos discover?
CLOSEDQUORUM is a Windows implant analyzed by Cisco Talos that delegates tactical command-and-control decisions to multiple commercial large language models. Talos said it has not confirmed in-the-wild deployment, but the research demonstrates how AI can remove the human operator from part of an attack chain.
What was notable about Cisco's MLPerf Inference v6.1 submission?
MLCommons identified Cisco's submission as the benchmark's first cross-vendor heterogeneous accelerator deployment, combining eight NVIDIA H200 GPUs and eight AMD Instinct MI350X GPUs in one inference pool connected by a Cisco G200 network.
What is VAST DataEnclave and how is Cisco involved?
VAST DataEnclave is a confidential AI runtime built on NVIDIA Confidential Computing that is designed to protect sensitive enterprise data and proprietary model weights during processing. VAST says the capability is in preview and is planned to ship in Q1 2027 through VAST and participating OEM partners including Cisco and Supermicro.
What is Cisco changing in its LLM Security Leaderboard?
Cisco expanded the LLM Security Leaderboard beyond text to include image and audio attack testing. The update adds multimodal scores so organizations can evaluate model security against the actual input types their AI agents use.
Sources
- Cisco Newsroom - Cisco AI Research: AgenticOps Scaling Quickly in the Enterprise, September 23, 2026.
- Network World - Increasing Complexity Drives Network Pros to Cede Control to AI, September 23, 2026.
- Cisco Talos - The Closed Quorum: Inside the First Reported Autonomous AI C2 Implant, September 22, 2026.
- Wired - A New Tool Found Malware Guided by an AI Hive Mind, September 22, 2026.
- University of Notre Dame - Notre Dame Athletics Selects Cisco to Enhance Campus-Wide Network Connectivity, September 22, 2026.
- Cisco Blogs - Industry's First MLPerf Inference Benchmarking Across Multi-Vendor Accelerators, September 21, 2026.
- MLCommons - Where the Industry Is Investing: A Look at MLPerf Inference v6.1, September 2026.
- Cisco Blogs - Building a Trusted Foundation for Confidential AI, September 24, 2026.
- VAST Data - VAST Data Introduces DataEnclave, September 22, 2026.
- Cisco Blogs - LLM Security Leaderboard Now Ranks Every Modality Where Agent Risk Lives, September 24, 2026.