Skip to content
Tech News
clear
Topics: Today This Week This Month This Year

US agencies accuse DeepSeek, Alibaba and other Chinese AI firms of mass model distillation

The NSA, CISA and FBI issued a joint advisory alleging that Chinese AI companies including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI extracted billions of tokens from US frontier models such as Claude, GPT, Gemini and Grok since 2024. The agencies say this data was used to train competing systems like DeepSeek's R1 and Moonshot's Kimi K2/K3, describing the practice as 'distillation activities at an industrial scale.'

AI gateways alone can't stop drift, data leaks, or memory poisoning in agents

Security researchers warn that enterprises deploying AI agents are prioritizing gateway controls before establishing the identity and attribution systems those gateways depend on. A real-world example cited is a LiteLLM flaw added to CISA's Known Exploited Vulnerabilities catalog in June, which let attackers run commands on the host without credentials, one of seven vulnerabilities found in that gateway in a single month. Analysts argue gateways should be the fifth layer of defense, not the first, since without knowing which agent is acting and why, enforcement systems can't tell legitimate actions from technically permitted but inappropriate ones.

CISA gives federal agencies until Saturday to patch Citrix NetScaler flaw CVE-2026-8452

CISA has added CVE-2026-8452, a memory overflow bug in Citrix NetScaler ADC and Gateway appliances, to its Known Exploited Vulnerabilities catalog, requiring federal civilian agencies to patch by August 29. Originally described by Citrix as only enabling denial-of-service, researchers at watchTowr later demonstrated it can be exploited for root-level remote code execution, and reports indicate attackers are already deploying web shells on unpatched systems.

CISA says over 100 US water systems hit in July cyberattack wave

CISA disclosed that hackers breached more than 100 internet-exposed water and wastewater systems across the U.S. during July, expanding the known scope of an ongoing campaign already reported in Michigan, Minnesota and other states. The attackers primarily targeted programmable logic controllers from vendors like Rockwell, Schneider Electric and Siemens, in some cases disabling shutdown alarms and safety processes without alerting operators.

Attackers exploit Zimbra RCE flaw, compromise 274 servers worldwide

Shadowserver identified 274 Zimbra Collaboration Suite instances already breached through exploitation of CVE-2026-73570, a command injection flaw in the SNMP monitoring component that allows unauthenticated remote code execution. Synacor patched the bug in ZCS 10.1.20 on July 20, but Shadowserver still counts over 8,200 unpatched instances exposed online, though not all are necessarily exploitable due to non-default configuration requirements.

CISA gives federal agencies 3 days to patch actively exploited Zimbra RCE bug

CISA has ordered federal civilian agencies to fix CVE-2026-73570, a Zimbra Collaboration Suite flaw allowing unauthenticated attackers to run arbitrary commands via crafted SMTP requests when SNMP notifications are enabled. Zimbra released a fix in version 10.1.20 on July 20, but CERT Polska flagged active exploitation last week, and Shadowserver has already identified over 270 compromised Zimbra servers among more than 12,000 exposed online.

Today's top topics: openai apple anthropic artificial intelligence qualcomm claude opus 5.5 iphone 18 pro ai safety motorola signature 27 sam altman
View all today's topics →