NSA

8 items · Policy 2 · Defense 1 · Attacks 5 · all entities

The Chinese Communist Party's own newspaper rejects the US distillation allegations and warns of countermeasures

A People's Daily commentary rejected the US allegation that Chinese AI companies ran industrial-scale distillation against American frontier models as “without factual or legal basis,” accused Washington of “politicising” a normal technical and commercial practice, and said Beijing would take “countermeasures” if the allegation were used as a pretext to suppress Chinese companies' development. The allegation was made in the September 8 NSA/CISA/FBI joint advisory that named six Chinese labs; China's commerce ministry rejected it on September 10, and the Party newspaper's commentary lands ahead of a Xi–Trump meeting expected on September 24.

Reported by pressPeople's Daily (via South China Morning Post) ↗ ·

NSA splits into five mission centres, one of them for artificial intelligence

Army Gen. Joshua Rudd, who leads both the National Security Agency and US Cyber Command, is reorganising the agency into five mission centres — China, cybersecurity, artificial intelligence, combat support and global intelligence , each with its own chief. The Record reports that the announcement started a 30-day clock for the directors to submit redesigns, that the centres are expected to reach full operational capability by January, that the head of the AI centre has been selected but not named, and that it is unclear what becomes of existing bodies such as the Cybersecurity Collaboration Center.

Reported by pressThe Record (Recorded Future News) ↗ ·

Anthropic names seven China-based AI companies it says ran industrial-scale distillation against Claude

The Hacker News, reading Anthropic's September 2026 misuse report, says the company attributes illicit distillation campaigns to seven China-based labs and gives each a tracking identifier: Alibaba (GTG-16005), Moonshot AI (GTG-16002), DeepSeek (GTG-16001), Zhipu/Z.ai (GTG-16006), Xiaomi (GTG-16008), SenseTime (GTG-16012) and MiniMax (GTG-16003). It reports 151 million exchanges attributed to Alibaba from more than 3,500 fraudulent accounts between May and July 2026, 23 million to Moonshot from 5,380 accounts over the same window with almost 300,000 customer requests relayed in ten days, and more than 12.1 million to DeepSeek over 14 days in July. Five of the seven — Alibaba, Moonshot, DeepSeek, Z.ai and MiniMax — also appear in the September 8 NSA/CISA/FBI advisory; Xiaomi and SenseTime do not, and StepFun, which the advisory names, is not among Anthropic's seven.

Reported by pressAnthropic (via The Hacker News) ↗ ·

NSA, CISA and FBI name six China-based AI companies running industrial-scale distillation campaigns against US frontier models

The joint advisory says DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI “extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models” — naming the Claude, GPT, Gemini and Grok families — “since at least late 2024,” routed through a gray market of API proxies the advisory calls “transfer stations,” which resell frontier-model access below official prices, and through pools of accounts running concurrent sessions with load distribution. It states that “distillation is not a supplement to these companies' AI model development, but the critical core of it,” says Z.AI distilled “billions of tokens of GPT-5.5 data and Claude Opus 4.8 data,” and calls DeepSeek's publicly quoted $5.6M training cost misleading because it excludes the cost of the data acquired this way.

On the recordNSA / CISA / FBI ↗ ·

FBI, NSA and Cyber National Mission Force say a China-linked group has been integrating AI into its operations

A joint advisory attributes the group it tracks as QTFY to Nanjing Xinjiuwei Network Technology Co. and describes malicious distributed platforms used against defense industrial base, communications, government, higher education, energy, information technology and water and wastewater targets. The advisory states the actors “have also been observed heavily researching and integrating AI into their processes over the last two years.”

US agencies warn attackers are using AI-generated scripts to target Siemens S7 industrial controllers

A joint advisory (AA26-231A) from the NSA, CISA, FBI, DOE and EPA warned that threat actors are running persistent reconnaissance and capability development against internet-exposed Siemens S7 programmable logic controllers with weak or default credentials, and are using AI-assisted development to rapidly iterate exploit code — including AI-generated Python scripts that call the snap7.dll library to read PLC memory and configuration. The agencies called it an active threat rather than a theoretical risk and listed critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities as targeted sectors; no threat actor was attributed.

On the recordNSA / CISA / FBI / DOE / EPA ↗ ·

Seventeen agencies update the minimum elements for a software bill of materials, and leave AI systems to separate guidance

CISA, NSA, FBI and international partners including Australia, Canada, Czechia, France, Germany, India, Italy, Japan, South Korea, the Netherlands, New Zealand, Poland and Slovakia updated the 2021 NTIA baseline, adding ten data elements including SBOM Author Signature, Component Hash Value and Component License. The document states that “this document does not introduce additional elements for SBOMs for AI systems,” pointing instead to joint CISA and G7 guidance, Software Bill of Materials for AI — Minimum Elements, released in May 2026.

US advisory: Iran-linked actors manipulating Rockwell, Siemens and Schneider PLCs

A US government advisory (CISA/FBI/NSA/EPA), updated July 22, warns Iran-linked actors are using vendors' own engineering software to alter project files on Rockwell, Siemens (S7-1200) and Schneider (Modicon M340) PLCs — disabling shutdown and alarm logic at US water, energy and government facilities, with at least one confirmed US victim. No direct AI angle, but a strategically significant critical-infrastructure escalation.

Confirmed by orgSecurityWeek ↗ ·