Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability
Cisco patched an sftunnel flaw in Secure Firewall Management Center letting an authenticated remote attacker execute arbitrary commands as root.
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center allows an authenticated remote attacker to execute commands as root. The flaw stems from incorrect permissions allowing a registered sftunnel peer to write an arbitrary file anywhere on the device, exploitable via connection hijacking or crafted sftunnel commands. Cisco has released software updates.
China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
NSA, CISA, and FBI warn DeepSeek, Alibaba, and other Chinese AI firms ran industrial-scale distillation of U.S. frontier models, threatening U.S. AI leadership.
A joint NSA, CISA, and FBI Cybersecurity Advisory (AA26-251A) says China-based firms DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens from U.S. frontier models including Claude, GPT, Gemini, and Grok, likely with Chinese government knowledge. Campaigns running since at least late 2024 used native APIs, cloud providers, third-party aggregators, gray-market proxy "transfer stations", and shared premium subscriptions to bypass geographic restrictions, evade safeguards, and violate providers' terms of use. The agencies recommend detecting anomalous prompts, accounts, and usage patterns; subtly altering responses to suspected distillers; and cross-organization intelligence sharing. They also call DeepSeek's publicly cited $5.6M training cost misleading because it excludes data acquired through distillation.