CISO Daily Digest: NSA-FBI-CISA Accuse Six Chinese AI Firms of Industrial-Scale Model Distillation (20260909)
The NSA, FBI and CISA jointly accuse DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI of running industrial-scale distillation campaigns against US frontier models (Anthropic Claude, OpenAI GPT, Google Gemini, SpaceXAI Grok) since at least 2024, likely with Chinese government awareness — Beijing rejects the claims. Also: Microsoft's record 974-CVE Patch Tuesday fixes two exploited Windows zero-days (CVE-2026-81963, CVE-2026-85880) now KEV-listed; Chrome patches its seventh exploited zero-day of 2026 (CVE-2026-87491); CISA orders federal patching of StyleSmuggler CVE-2026-75650 and N-able N-central CVE-2026-86218 by September 11; Calif's zero-click WeChat worm; Check Point's ChatGPT cross-account isolation bypass; DeepSeek Harness CVE-2026-82533; Okta finds 1,843 unexpired AI tokens in a stealer dump; and a new Shai-Hulud wave (Trinitite) hits a TanStack Query npm tool.
NSA, FBI and CISA Accuse Six Chinese AI Firms of Industrial-Scale Frontier-Model Distillation
On September 8, the NSA, FBI and CISA issued a joint cybersecurity advisory accusing six China-based AI companies — DeepSeek, Moonshot AI (Kimi maker), Alibaba, MiniMax, StepFun and Z.AI — of running what the agencies called “aggressive, malicious, and targeted distillation activities at an industrial scale” to extract “restricted proprietary functionalities and capabilities of US frontier AI models.” The advisory says the campaigns date back to at least late 2024 and targets models from Anthropic (Claude), OpenAI (GPT), Google (Gemini) and SpaceXAI (Grok), with the extracted capabilities reportedly used to improve the Chinese firms’ own models, including math and code-review abilities.
The agencies detailed an industrial-ingestion playbook: Chinese developers allegedly bulk-purchased premium subscriptions to US AI services and shared them across teams of developers to cut costs, and routed distillation requests through multiple pathways to gain unauthorized access, violating US providers’ terms of use. The statement assesses the activity was carried out “likely with Chinese government awareness” and warns that such distillation lowers Chinese R&D costs while advancing capabilities that US officials say could be used against the United States and its allies in military and cyber operations (per Reuters). The advisory also urged Silicon Valley developers to protect their model access and outputs.
Beijing rejected the allegations on September 9. Foreign Ministry spokesperson Mao Ning urged the US to “refrain from making unfounded accusations or smears,” saying “China’s AI development is the result of high-level technological self-reliance and strength.” The exchange lands weeks before a planned Xi Jinping visit to Washington on September 24, with US-China AI-safety talks expected in mid-September — and follows a similar US accusation in April ahead of Trump’s Beijing trip, plus prior private claims by Anthropic and OpenAI and a July 31 Reuters report that Chinese military researchers train PLA systems on US frontier-model outputs.
Why This Reshapes AI Supply-Chain and Model Governance
- A new class of government advisory: this is the first joint US intelligence/law-enforcement/cyber advisory squarely targeting model distillation — elevating what were previously vendor disputes (Anthropic and OpenAI’s own accusations) into a formal US government finding with export-control and compliance ripple potential for every enterprise that consumes or provides frontier-model APIs.
- The subscription layer is the attack surface: bulk-shared premium accounts and API access are the ingestion mechanism for the alleged theft — the same class of credentials that today’s Okta AI-token research (below) shows being replayed from infostealer logs. Enterprise AI governance now spans session tokens, API keys and terms-of-use enforcement, not just model choice.
- Escalation asymmetry before the summit: China’s flat rejection and the September 24 summit timing mean reciprocal measures (model-access restrictions, export rules, data-localization demands) are plausible on both sides; organizations with AI toolchains spanning US and Chinese providers face growing compliance and supply-chain review pressure.
🔗 Reference: Coverage from (qz.com, Business Standard — Bloomberg, The CyberInsider, India Today)
Active Threats This Week
📌 Record Patch Tuesday: Microsoft fixes 974 CVEs, including two exploited Windows zero-days (CVE-2026-81963, CVE-2026-85880) Microsoft’s September Patch Tuesday is its largest ever: 974 CVE-numbered fixes — more than double August’s 421 — plus 25 third-party component advisories, for 999 total. Windows leads with 723 fixes, followed by Office (111) and SQL Server (62). Two of the flaws are zero-days already exploited in the wild, both local privilege escalations rated CVSS 7.8 that hand attackers SYSTEM privileges: CVE-2026-81963, a link-following flaw in the Windows Update Stack affecting all Windows 11 versions and Windows Server 2025; and CVE-2026-85880, a heap-based buffer overflow in ALPC affecting Windows 10 (1607/1809/22H2) and Windows Server 2012–2022. CISA added both to its Known Exploited Vulnerabilities catalog on September 8 with a federal remediation deadline of September 22. 🔗 Reference: KrebsOnSecurity | iThome — 破紀錄修補規模 | iThome — 兩個零時差漏洞細節
📌 CISA KEV: StyleSmuggler (CVE-2026-75650) and N-able N-central (CVE-2026-86218) must be patched by September 11 CISA’s September 8 warning added four actively exploited flaws to the KEV catalog. Besides the two Microsoft zero-days above, the catalog now includes Adobe Commerce/Magento’s StyleSmuggler CVE-2026-75650 (CVSS 10.0 template-engine flaw exploited to backdoor online stores — the lead story of our September 6 digest, emergency-patched September 7) and N-able N-central’s CVE-2026-86218 (CVSS 10.0 pre-authentication static-code-injection RCE — our September 8 lead). Federal agencies must remediate the Magento and N-central flaws by September 11; the Microsoft pair is due September 22. 🔗 Reference: iThome — CISA KEV 新增四漏洞
📌 Chrome 153 patches 230 flaws, including V8 zero-day CVE-2026-87491 — the seventh exploited Chrome zero-day of 2026 Google’s Chrome 153 release (September 8) — the first of its planned two-week cadence — fixes 230 vulnerabilities (5 critical, 41 high, 133 medium, 51 low), including CVE-2026-87491, an out-of-bounds write in the V8 JavaScript engine that Google says is exploited in the wild; NVD notes a crafted HTML page can trigger arbitrary code execution inside the browser sandbox. It follows CVE-2026-85046, another V8 zero-day fixed less than a week earlier (covered in our September 4 digest) — making seven exploited Chrome zero-days so far in 2026. The update also fixes five critical WebGL/Cast flaws. Users should update to 153.0.8010.36/.37 (Windows/macOS); Chromium-based browsers (Edge, Brave, Vivaldi) need matching updates. 🔗 Reference: The Hacker News | iThome
📌 Zero-click WeChat worm ‘WeWorm’ takes over accounts via incoming calls, spreads across iOS and Android Security firm Calif demonstrated WeWorm, a zero-click exploit in WeChat’s voice-call handling: an attacker calling from the victim’s own contact list can take over the WeChat account while the phone is still ringing — the victim does not need to answer or touch the device, and answering does not stop the attack (only declining ends that attempt, and the attacker can simply call again). Once compromised, the account can read/send messages, make calls, and act as its owner — and can call further contacts, enabling cross-platform worm propagation (demo: Android → iPhone → Android). Calif reported the flaw to Tencent in July; Tencent’s August 21 releases (Android 8.0.77, iOS 8.0.76) mitigated it, and Calif confirmed on August 28 that server-side measures blocked the exploit for all users. No real-world attacks have been reported; WeChat/Weixin had 1.439 billion combined monthly active users as of June 30, 2026. Tencent confirmed to researchers on September 4 that the flaw could enable remote command execution. 🔗 Reference: The Hacker News | iThome
📌 ChatGPT cross-account isolation bypass: planted prompt quietly exfiltrates a victim’s connected-app data Check Point Research disclosed a ChatGPT architecture flaw: code-execution sandboxes for different accounts are isolated from the internet and from each other, but they share an internal JFrog Artifactory package service whose metadata is writable — turning it into a hidden cross-account channel. A single instruction planted in a victim conversation (via pasted prompt, a shared ChatGPT conversation, or custom-GPT builder instructions) made ChatGPT run two parallel streams in Thinking mode: answering the user normally while fetching attacker tasks from the hidden channel, executing them with the victim session’s tools and connected-app permissions, and returning results to the attacker’s account. The PoC read the victim’s Gmail and exfiltrated it — visible to the user only as a small “Talked to Gmail” label. The channel could also copy chat history and files. OpenAI has decommissioned the affected Artifactory instance, and the researchers say the channel is no longer usable. 🔗 Reference: The Hacker News | iThome
📌 DeepSeek Harness flaw CVE-2026-82533 (CVSS 9.4): an AI coding agent can disable its own sandbox OX Research found that DeepSeek Harness — DeepSeek’s open-source tool for running AI coding agents — let a sandboxed agent turn off its own sandbox with a single command: by calling the tool’s unauthenticated local web interface and switching its session to danger-full-access mode, the agent escaped the file sandbox and ran outside it without any approval prompt. The flaw (tracked as CVE-2026-82533, rated 9.4 by VulnCheck) worked on default installations until DeepSeek’s August 27 fix, and required attacker-supplied text in the agent’s context to trigger. Sandbox escapes in AI coding agents are a growing enterprise concern as agentic tooling gains access to source trees and CI credentials. 🔗 Reference: The Hacker News
📌 Okta: a single 7 GB stealer dump exposed 1,843 unexpired AI session tokens that bypass MFA Okta’s analysis of a 7 GB infostealer dump released on Telegram on August 2 found data from 5,871 infected machines across 162 countries, including thousands of unexpired authentication tokens for Google, Microsoft, Anthropic, Amazon, Notion, Character.ai, Cursor, Poe and others. Of 44,791 unique JWTs, 555 were likely AI-service authentication tokens, and the dump contained 1,843 unexpired JWTs/JWEs on release day. Okta warns these “skeleton keys” can be replayed to log into LLM services without credentials, bypassing MFA — matching recent reports of stolen Claude and other AI tokens circulating after account sessions were compromised. Stealers such as Lumma and Vidar are the harvesting layer. 🔗 Reference: The Hacker News
📌 Shai-Hulud returns: TanStack Query codegen npm tool poisoned with the ‘Trinitite’ worm (JFrog) JFrog disclosed a new wave of the Shai-Hulud supply-chain campaign: on August 28 it found the npm package @7nohe/openapi-react-query-codegen — a TanStack Query code-generator with 150,000+ weekly downloads — distributing a new Mini Shai-Hulud worm family dubbed Trinitite. Attackers abused the project’s GitHub Actions workflow, which mistook a “npm publish” comment on a pull request for a release command without verifying the commenter’s identity; eight official versions were infected. Trinitite executes at npm install time, hiding its commands in obfuscated Python so scanners that only inspect package.json scripts miss it, then harvests GitHub, npm, PyPI, RubyGems, cloud, Kubernetes and Vault credentials and exfiltrates them (encrypted) to an attacker-controlled GitHub repository — using npm publish rights to spread further. JFrog has not confirmed victims or attribution, but notes discovery came about a day after Australia arrested a suspected TeamPCP member. 🔗 Reference: iThome
📌 Business Weekly Group (商周集團) and Cite Media sites knocked offline by an attack Taiwan’s 商周集團 (Business Weekly Group), part of the Cite Media Holding Group (城邦媒體控股集團), said on September 9 that its websites were hit by a malicious attack; online services were down and full restoration will take time, with third-party teams engaged for forensics and recovery. Cite Media told iThome the attack on the group’s websites and online services occurred September 8. Print magazine publication and distribution are unaffected; the impact scope has not been disclosed. 🔗 Reference: iThome
📌 Thomson Reuters C-Track court-platform breach: SSNs and sealed records exposed across 12 US states and Canadian courts Thomson Reuters’ C-Track court case-management platform suffered a data breach: an unauthorized third party accessed court files — first spotted by Thomson Reuters on June 30 and traced back to March. Exposed data may include names, Social Security numbers, driver’s license numbers, birth dates and medical/health insurance information, and for some courts confidential, sealed or redacted records. Per court notices aggregated by The Record, at least 12 US states are affected — including 10 Ohio district appellate courts and courts in the US Virgin Islands — plus three courts in Ontario, Canada. Thomson Reuters says the incident did not originate in the courts’ own networks; total data volume and victim counts remain undisclosed. 🔗 Reference: iThome
📌 Truffle Security: 9,300+ leaked AWS keys still valid — 768 hold full control of enterprise accounts Truffle Security tracked AWS access keys leaked between August 2022 and August 2026 across Git repositories/history, Hugging Face datasets, Docker images, package registries and CI logs: 64,024 keys mapping to 50,654 AWS accounts. Of 10,616 keys with full verifiable credentials, 88% (9,300+) were still valid as of August 10. Among the live keys, 768 had complete control of enterprise accounts — 526 AWS root keys and 242 IAM keys with AdministratorAccess. Key hygiene is poor: 86% of dated keys were never rotated, median age is 5 years (oldest: 17). Hugging Face is the largest leak source (8,300+ keys), and Truffle notes deleted source files do not remove keys already ingested into public datasets. 🔗 Reference: iThome
How Can OPSWAT Help
Two threads in today’s digest are squarely file-borne. The Trinitite npm worm rides inside legitimate-looking package tarballs and executes at install time, with payload logic hidden in obfuscated Python — the kind of artifact that only multi-engine scanning plus content disarm and reconstruction can inspect before it reaches developer machines and CI runners. And the leaked-AWS-key epidemic traces back to secrets committed into source files, datasets and container images that circulate through package ecosystems and model hubs. MetaDefender Multi-Scan (30+ anti-malware engines) and MetaDefender CDR (deep content disarm and reconstruction for archives, installers and code artifacts) let organizations inspect downloads and published packages before use, while MetaDefender Kiosk covers air-gapped transfer scenarios for regulated environments.