The NSA, CISA and FBI issued a joint advisory alleging that Chinese AI companies including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI extracted billions of tokens from US frontier models such as Claude, GPT, Gemini and Grok since 2024. The agencies say this data was used to train competing systems like DeepSeek's R1 and Moonshot's Kimi K2/K3, describing the practice as 'distillation activities at an industrial scale.'
Security researchers warn that enterprises deploying AI agents are prioritizing gateway controls before establishing the identity and attribution systems those gateways depend on. A real-world example cited is a LiteLLM flaw added to CISA's Known Exploited Vulnerabilities catalog in June, which let attackers run commands on the host without credentials, one of seven vulnerabilities found in that gateway in a single month. Analysts argue gateways should be the fifth layer of defense, not the first, since without knowing which agent is acting and why, enforcement systems can't tell legitimate actions from technically permitted but inappropriate ones.
CISA has added CVE-2026-8452, a memory overflow bug in Citrix NetScaler ADC and Gateway appliances, to its Known Exploited Vulnerabilities catalog, requiring federal civilian agencies to patch by August 29. Originally described by Citrix as only enabling denial-of-service, researchers at watchTowr later demonstrated it can be exploited for root-level remote code execution, and reports indicate attackers are already deploying web shells on unpatched systems.
CISA disclosed that hackers breached more than 100 internet-exposed water and wastewater systems across the U.S. during July, expanding the known scope of an ongoing campaign already reported in Michigan, Minnesota and other states. The attackers primarily targeted programmable logic controllers from vendors like Rockwell, Schneider Electric and Siemens, in some cases disabling shutdown alarms and safety processes without alerting operators.
Shadowserver identified 274 Zimbra Collaboration Suite instances already breached through exploitation of CVE-2026-73570, a command injection flaw in the SNMP monitoring component that allows unauthenticated remote code execution. Synacor patched the bug in ZCS 10.1.20 on July 20, but Shadowserver still counts over 8,200 unpatched instances exposed online, though not all are necessarily exploitable due to non-default configuration requirements.
CISA has issued an emergency directive requiring federal agencies to fix a Zimbra vulnerability, tracked as CVE-2026-73570, within just three days. The flaw is severe enough that exploitation could give an attacker complete control over a victim's email and communications.
CISA has ordered federal civilian agencies to fix CVE-2026-73570, a Zimbra Collaboration Suite flaw allowing unauthenticated attackers to run arbitrary commands via crafted SMTP requests when SNMP notifications are enabled. Zimbra released a fix in version 10.1.20 on July 20, but CERT Polska flagged active exploitation last week, and Shadowserver has already identified over 270 compromised Zimbra servers among more than 12,000 exposed online.