New Given root inside a sandbox, four frontier models found their way back out to the network
Perplexity's Secure Intelligence Institute reports a month-long red team of SPACE, the Firecracker-based microVM sandbox behind Perplexity Computer, in which nine model configurations — among them Claude Opus 5.0, GPT-5.6 Sol, GPT-5.6 Cyber, Gemini 3.1 Pro, Kimi K3, GLM 5.2, Grok 4.20, DeepSeek V4 Pro and Qwen 3.8 27B — were given root inside the guest VM and, in some runs, the sandbox source code. No run escaped the VM-to-host boundary in 108 attempts, and no run beat a no-network configuration in 54 attempts; with partial network access allowing package repositories, four models got out, using forged DNS responses and the shared IP addresses of public package CDNs. The institute says "eight of the ten third-party sandbox platforms" it also tested "exhibited at least one network-policy bypass," and cautions that "cases in which the boundaries held should not be interpreted as evidence that they are perfectly secure."
One operator ran three open-source AI harnesses against online retailers at about $25 a company
Gambit Security's Eyal Sela reports a campaign running since July in which a single operator chained three agent harnesses bought through OpenRouter — Strix for vulnerability search (GLM 5.2, later DeepSeek v4 Pro), Cairn for exploitation (DeepSeek v4.1 Flash) and the open-source Hermes agent for orchestration (Anthropic's opus-4.6). “Between 10 and 15 September alone, 105 attack projects were launched and at least 27 companies were compromised to varying degrees,” including at least 600,000 unexpired credit card details from two of them; “skimmers were ordered against at least 27 named victims and confirmed in place on 19 of them.” The operator's own cost review gives “a mean of $25.46 over 101 completed scans,” against about $7,006 of model spend in four weeks. Gambit names no operator and says errors are possible at this stage of the analysis.
Cisco Talos documents a Windows implant that lets four AI models vote on its next move
Talos describes CLOSEDQUORUM, a 16.4MB 64-bit Windows executable compiled in Go that queries DeepSeek, Qwen, Mistral and Google Gemini and executes whichever post-compromise action wins a plurality vote, with DeepSeek breaking ties; its capabilities include LSASS credential dumping, browser password theft and process injection. Talos calls it "to our knowledge, the first publicly documented Windows implant to apply this model to tactical command and control (C2)" and says "we do not have confirmation of in-the-wild deployment," though binary artifacts tie the developer to carding-forum postings dating to 2025.
Microsoft says attackers are now using the AI brands themselves as the lure
In “Detect and disrupt AI-themed attacks with Microsoft Defender,” Microsoft describes phishing, malware and credential-theft campaigns impersonating ChatGPT, Microsoft Copilot, DeepSeek and Claude. It says a ChatGPT-themed phishing kit built to harvest credit card data drove a campaign that “sent up to 100,000 emails in a single day,” that fraudulent DeepSeek installers were distributed through GitHub, that malvertising for a fake AI Windows plugin delivered the Vidar stealer, and that Claude-themed pages were used for adversary-in-the-middle credential harvesting. It says an initial access broker it tracks as Storm-3075 “used AI-themed malvertising to distribute payloads for multiple downstream actors.”
Anthropic names seven China-based AI companies it says ran industrial-scale distillation against Claude
The Hacker News, reading Anthropic's September 2026 misuse report, says the company attributes illicit distillation campaigns to seven China-based labs and gives each a tracking identifier: Alibaba (GTG-16005), Moonshot AI (GTG-16002), DeepSeek (GTG-16001), Zhipu/Z.ai (GTG-16006), Xiaomi (GTG-16008), SenseTime (GTG-16012) and MiniMax (GTG-16003). It reports 151 million exchanges attributed to Alibaba from more than 3,500 fraudulent accounts between May and July 2026, 23 million to Moonshot from 5,380 accounts over the same window with almost 300,000 customer requests relayed in ten days, and more than 12.1 million to DeepSeek over 14 days in July. Five of the seven — Alibaba, Moonshot, DeepSeek, Z.ai and MiniMax — also appear in the September 8 NSA/CISA/FBI advisory; Xiaomi and SenseTime do not, and StepFun, which the advisory names, is not among Anthropic's seven.
Hundreds of AI agents drive a PaperCut campaign reaching 440 instances in 48 countries
GreyNoise reported a campaign against PaperCut MF/NG in which an actor deployed hundreds of AI agents powered by OpenAI's Codex harness and a DeepSeek model, compromising at least 440 instances hosted by 395 identified victim organizations in 48 countries through CVE-2026-81578 and CVE-2026-82078. It records eleven organizations compromised in 26 seconds and a fastest run from initial access to full domain administrator of seven minutes, attributing the activity to a likely Russian-speaking actor.
A flaw in DeepSeek's agent harness let a sandboxed agent turn its own confinement off with one command
OX Research disclosed CVE-2026-82533 in DeepSeek Harness, in which the local agent-control API “read the 'Host' request header and allowed access if the value was a loopback authority” but “never compared that value with the connection's actual peer address,” so that “a sandboxed AI agent could use a single shell command to call that API and elevate its own session to 'danger-full-access' with approval prompts disabled.” The OpenCVE record, published September 8 with VulnCheck as the assigning authority, covers all versions before 0.1.2-alpha.1 and carries CVSS 9.4 under v4.0 and 9.6 under v3.1. OX says the fix shipped in 0.1.2-alpha.1 on August 27 and that it re-tested the patched build on August 30; it demonstrated the flaw on a default installation and claims no exploitation in the wild.
NSA, CISA and FBI name six China-based AI companies running industrial-scale distillation campaigns against US frontier models
The joint advisory says DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI “extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models” — naming the Claude, GPT, Gemini and Grok families — “since at least late 2024,” routed through a gray market of API proxies the advisory calls “transfer stations,” which resell frontier-model access below official prices, and through pools of accounts running concurrent sessions with load distribution. It states that “distillation is not a supplement to these companies' AI model development, but the critical core of it,” says Z.AI distilled “billions of tokens of GPT-5.5 data and Claude Opus 4.8 data,” and calls DeepSeek's publicly quoted $5.6M training cost misleading because it excludes the cost of the data acquired this way.
Independent benchmark reports open-weight models matching closed frontier models at vulnerability discovery for about half the cost
Security vendor Aikido ran ten models three times each against 32 freshly disclosed CVEs in a bounded harness with no internet access and frozen prompts, and reported that open-weight models matched or beat closed frontier models on pooled pass@3 recall: DeepSeek V4 Pro found 28 of 32, ahead of Claude Opus 5 and Grok 4.6 at 26 of 32, while three DeepSeek Pro runs cost about $295 against roughly $450–$590 for a single frontier pass. Aikido measured other developers' models with its own harness and none of the scores has been independently reproduced.
Researchers show self-propagating "mind virus" payloads can spread between LLM agents, and that one warning line largely stops them
In a paper titled "Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems" (Papadopoulos, Shah, Zimmerman and Lindsey), researchers demonstrated that goal-carrying payloads can spread from one AI agent to another through ordinary communication and through persistent prompt and memory files, such as SOUL.md and MEMORY.md, that survive session resets. Frontier models proved more resistant than open-weight models such as DeepSeek V3 and Qwen 2.5, a single warning line in the system prompt cut susceptibility to near zero, and the authors reported no successful agent-to-agent spread in deployed systems.
Unit 42 reports Chinese-speaking actor running autonomous attacks with DeepSeek and the Hermes Agent framework
Palo Alto Networks Unit 42 documented a Chinese-speaking threat actor using aliases knaithe and KnYuan who wired DeepSeek into the Hermes Agent framework and orchestrated it over Telegram to autonomously enumerate vulnerabilities, source exploits and launch attacks, including FOFA-driven scanning for exposed Langflow and n8n instances. The autonomous exploitation attempts failed against authenticated targets, and the actor's successful compromises came from manual operations; OpenAI confirmed its provider-side safeguards refused policy-violating requests and disabled an account it believes is linked to the campaign.
UK AISI puts leading open-weight models four to seven months behind the closed cyber frontier
AISI reports that GLM-5.2 and DeepSeek V4-Pro perform similarly to closed frontier models released four to seven months before them, narrowing from the six to ten months it measured through most of 2025. It puts a 100-million-token cyber range run at about $85 for Opus 4.5 and 4.6, about $46 for GLM-5.2 and $1.19 for DeepSeek V4-Pro.
Hunt.io reports suspected China-linked operators running Claude Code and DeepSeek as an intrusion toolchain against government targets in four countries
Hunt.io analysed an exposed open directory containing 2,431 files, including operator logs of LLM sessions, and described a split-model workflow in which Claude Code acted as the execution engine for agentic tool use, bash execution and session persistence while DeepSeek-v4-pro handled attack logic, script generation and decision-making. Hunt.io reported exploitation against an Afghan government application, a Thai government administrative system via SQL injection, and two Taiwanese critical-infrastructure organisations, with reconnaissance against US government entities and financial firms in Europe, Australia and Asia.