New NSA, CISA and FBI name six China-based AI companies running industrial-scale distillation campaigns against US frontier models
The joint advisory says DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI “extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models” — naming the Claude, GPT, Gemini and Grok families — “since at least late 2024,” routed through a gray market of API proxies the advisory calls “transfer stations,” which resell frontier-model access below official prices, and through pools of accounts running concurrent sessions with load distribution. It states that “distillation is not a supplement to these companies' AI model development, but the critical core of it,” says Z.AI distilled “billions of tokens of GPT-5.5 data and Claude Opus 4.8 data,” and calls DeepSeek's publicly quoted $5.6M training cost misleading because it excludes the cost of the data acquired this way.
New Google records an attacker planning, building and running a mass credential-harvesting campaign with an autonomous multi-agent framework in under six hours
In its September AI Threat Tracker, Mandiant reports a suspected financially motivated actor compromising an organisation's cloud infrastructure to deploy an autonomous, multi-agent attack framework: “The threat actor leveraged an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours,” using preconfigured markdown instruction sets as operational playbooks and compromising thousands of third-party credentials. A separate reconnaissance framework ran a production dashboard managing “over 23,800 harvested secrets in real time, including API keys for cloud and AI services.” Google adds that it “has not yet observed threat actors deploying fully autonomous pipelines against targets in the wild.”
New Google says a PRC-nexus actor runs open-weight models on victim compute to escape API monitoring, and that AI models and prompts are now extortion targets
The same report says GTIG observed suspected UNC6508 activity “compromising cloud environments to deploy local LLM infrastructure”: “By using a local, open-weight model deployed in compromised infrastructure, UNC6508 is able to avoid commercial AI API monitoring, while co-opting victim compute resources,” against academic, medical and military research institutions in North America. Mandiant separately investigated “multiple data theft extortion operations in which threat actors stole proprietary AI data, including models, skills, prompts, source code, and related research,” affecting technology, healthcare and media and entertainment companies in North America and Europe. Google also says it now sees coordinated distillation campaigns against its own models “on a regular basis, some exceeding 100 million prompts.”
A researcher publishes proof-of-concept zero-day exploits against CrowdStrike Falcon, Avast and Nvidia components
SecurityWeek reports that the researcher known as Nightmare Eclipse published three zero-days with proof-of-concept code: PrettyPrague, which targets the Avast sandbox to spawn a shell with full system privileges; FalconFlank, a privilege-escalation bug in the Office malicious-macro remediation feature of the CrowdStrike Falcon Sensor; and GreenSection, an out-of-bounds memory write affecting a shared global memory section used by multiple Nvidia user-mode components. Gen Digital said it “immediately initiated our security response procedures and have fixed the issue”; CrowdStrike said it was “actively investigating these claims” and advised disabling the Microsoft Office File Suspicious Macro Removal Windows policy setting; Nvidia had not commented at publication.