ZeroHour

Search: “creativity”

22 stories

China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies

NSA, CISA, and FBI warn DeepSeek, Alibaba, and other Chinese AI firms ran industrial-scale distillation of U.S. frontier models, threatening U.S. AI leadership.

A joint NSA, CISA, and FBI Cybersecurity Advisory (AA26-251A) says China-based firms DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens from U.S. frontier models including Claude, GPT, Gemini, and Grok, likely with Chinese government knowledge. Campaigns running since at least late 2024 used native APIs, cloud providers, third-party aggregators, gray-market proxy "transfer stations", and shared premium subscriptions to bypass geographic restrictions, evade safeguards, and violate providers' terms of use. The agencies recommend detecting anomalous prompts, accounts, and usage patterns; subtly altering responses to suspected distillers; and cross-organization intelligence sharing. They also call DeepSeek's publicly cited $5.6M training cost misleading because it excludes data acquired through distillation.

CISA Advisories · 8d agoAdvisory in the wild1

September 2026 Patch Tuesday forecast: All we need is more time

September 2026 Patch Tuesday forecast expects record CVE volume after August's 398 fixes, with SharePoint flaws CVE-2026-55040 and CVE-2026-63520 actively exploited.

This Patch Tuesday forecast column notes August 2026 Patch Tuesday was the second largest ever with 398 resolved CVEs, yet only one was confirmed actively exploited. SharePoint flaws CVE-2026-55040 and CVE-2026-63520 are being chained for authentication bypass and remote code execution in active attacks against unpatched servers. Microsoft Defender's ShieldBreak elevation of privilege flaw (CVE-2026-69414) is publicly disclosed with PoC code and a fix is expected, while Chrome CVE-2026-85046 was reported exploited in the wild. Several products, including Windows 11 24H2 Home/Pro and Exchange Server 2016/2019 ESU, reach end of support in October 2026.

Help Net Security · 7d agoAdvisory in the wildCVE-2026-55040CVE-2026-63520CVE-2026-62911+5 CVEs1

ISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th)

SANS Internet Storm Center publishes its daily Stormcast cybersecurity news podcast for Wednesday, September 9th, 2026.

The ISC Stormcast is the SANS Internet Storm Center's daily short-form cybersecurity news podcast. This item is the episode for Wednesday, September 9th, 2026, linking to the podcast detail page. No article content was included beyond the podcast link and Creative Commons license notice, so no specific incidents or topics are described.

SANS Internet Storm Center · 7d agoAdvisory

ISC Stormcast For Tuesday, September 8th, 2026 https://isc.sans.edu/podcastdetail/10084, (Tue, Sep 8th)

SANS Internet Storm Center's daily Stormcast podcast digest for September 8, 2026, summarizing current internet security activity.

The SANS Internet Storm Center published its daily Stormcast audio briefing for Tuesday, September 8, 2026. The available item text contains only licensing and URL metadata, with no specific vulnerabilities, incidents, or topics described.

SANS Internet Storm Center · 8d agoAdvisory

ISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd)

SANS Internet Storm Center released its daily Stormcast audio briefing for September 3rd, 2026.

The SANS Internet Storm Center published its regular daily Stormcast podcast episode. The feed text contains no substantive threat details, only the podcast link and licensing information. No specific incidents, vulnerabilities, or advisories can be extracted from the available text.

SANS Internet Storm Center · 13d agoAdvisory

ISC Stormcast For Wednesday, September 2nd, 2026 https://isc.sans.edu/podcastdetail/10078, (Wed, Sep 2nd)

SANS Internet Storm Center's daily Stormcast briefing for September 2, 2026; the feed carries no substantive story details.

This is the RSS shell for the ISC Stormcast daily podcast episode dated Wednesday, September 2, 2026. The provided text contains only licensing boilerplate and a link, with no incident, vulnerability, or threat details to extract.

SANS Internet Storm Center · 14d agoAdvisory

ISC Stormcast For Tuesday, September 1st, 2026 https://isc.sans.edu/podcastdetail/10076, (Tue, Sep 1st)

SANS Internet Storm Center's daily Stormcast podcast for September 1, 2026 summarizes current internet threat activity; no detailed content provided.

This is the daily ISC Stormcast audio briefing from the SANS Internet Storm Center for Tuesday, September 1st, 2026. No article body was provided, so the specific stories covered in this episode cannot be extracted. Stormcast episodes typically summarize notable internet-wide security events and handler findings.

SANS Internet Storm Center · 15d agoAdvisory