/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Allegations about cybersecurity company Cylance using bogus malware to close deals shed light on the complex nature of AV product testing in the industry

On the front lines of the antivirus industry's “testing wars.”  —  Last November, a systems engineer at a large company …

Ars Technica Sean Gallagher

Context & Ripple Effects

The allegation lands on a pattern the industry has seen before: in 2015, ex-employees said Kaspersky tricked rival antivirus programs into flagging false positives — the same playbook of manipulating tests rather than beating them. Cylance, which by its own reporting was growing revenue past $130M on an AI-detection pitch, now stands accused of planting bogus malware to make competitors look bad in sales demos.

What makes the story durable is that Cylance's core claim — machine learning outperforms signature-based scanning — is exactly what independent testing struggles to verify. Two years later, researchers showed they could fool Cylance's AI engine into classifying WannaCry and other real malware as benign, sharpening the question of whose tests buyers should trust at all.

First-order effects

  • Cylance's sales pipeline takes the direct hit: enterprise buyers evaluating it against incumbents like McAfee and Microsoft can no longer take vendor-run demos at face value, forcing every competitive bake-off toward third-party or customer-controlled test environments.

Second-order effects

  • Rival vendors gain a ready-made counter-narrative against Cylance's AI-first marketing — and, given the Kaspersky precedent, an incentive to audit each other's demo samples, turning testing itself into a competitive weapon.

Third-order effects

  • If vendor-supplied malware keeps proving unreliable, procurement shifts structurally toward independent labs and adversarial red-team validation as the default gate for AV purchases — with ML-based engines needing continuous, not point-in-time, certification.

The trend: Antivirus competition is shifting from detection claims to verification claims, as repeated manipulation and evasion episodes erode trust in vendor-controlled testing.