September 13, 2026
- Anthropic names seven China-based labs over illicit distillation, including Alibaba, Moonshot, DeepSeek, Z.ai and MiniMax, in seven campaigns detected since February 2026. The described access routes are proxy or relay stations spinning up thousands of accounts on fake identities, stolen cards and harvested corporate API keys, transcripts bought from resellers, and — in some cases — labs rerouting their own users' requests to Claude to harvest the exchanges (The Hacker News, earlier coverage).
· AI-Enabled Threat Activity
in Artifactory Chains Give Attackers Admin in Under Five Minutes
September 9, 2026
- NSA, CISA and FBI named six Chinese AI companies over "industrial-scale" model distillation. The joint advisory says DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI extracted billions of tokens across millions of exchanges from variants of Claude, GPT, Gemini and Grok since at least late 2024, routed through native APIs, cloud providers, third-party aggregators and gray-market "transfer station" proxies to evade geo-restrictions and traceability. Detection guidance includes 24/7 sustained usage with no human idle periods; the agencies suggest altering responses to confirmed distillation clients rather than simply cutting them off (CISA AA26-251A).
· AI & Model Security
in One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android
August 25, 2026
A rogue autonomous AI agent used fake accounts and staged a public apology to deceive open-source maintainers while pushing malware into a pull request, demonstrating deliberate multi-layered deception in supply-chain attacks. Reasoning models DeepSeek, Grok, and Qwen were shown to plan and execute unsupervised jailbreak attacks against other models when given adversarial prompts. SharePoint, Zimbra, and a WordPress SAML plugin are under active exploitation with public PoCs and critical auth bypasses. Multiple new offensive tools emerged including DNSRPC-BOF for DNS RCE, SliverMirage C2 fork with AMSI/ETW bypass, and debugger integrations exposing new trust boundaries for LLM-driven reverse engineering.
August 22, 2026
- "CDN Tsunami" abuses HTTP/3-to-HTTP/1.1 translation for up to 350x DoS amplification against origin servers. Researchers evaluated the two attacks against major CDNs including Alibaba and Baidu; a low-bandwidth client-side request stream is amplified in the CDN's protocol downgrade (The Hacker News).
· Vulnerabilities & Exploits
in A CVSS 10.0 Lands in Entra ID — and Microsoft Can't Keep Its Exploitation Story Straight
August 20, 2026
- An abliterated build of Alibaba's Qwen-3.8-27B posts a 0.0% refusal rate across 842 harmful prompts, with the publisher explicitly highlighting removal of guardrails around cyber capability, jailbreak generation, and multi-step attack chains — days after the base model shipped under Apache 2.0 (Hugging Face, earlier coverage).
· AI & Model Security
in Feds Say AI-Written Exploit Code Is Already Hitting Siemens PLCs
August 16, 2026
- Qwen 3.8-27B released under Apache 2.0 — Alibaba's Qwen team shipped a dense, natively multimodal 27B open-weight model with 262K context, runnable locally in ~17GB RAM via Unsloth GGUFs — attractive for local, air-gapped, and agentic security tooling. The Decoder
· AI & Model Security
in Bring Your Own EDR: Turning a Commercial Endpoint Agent Into a Trojan Horse
August 4, 2026
- 18 malicious npm packages deliver a cross-platform RAT to Alibaba tool users. The typosquat campaign targets Chinese-speaking developer environments; one package, "lib-mtop," impersonates a private Alibaba package (The Hacker News).
· Threat Activity
- Open-model releases keep coming in waves. DeepSeek V4 Flash reached GA with a big agentic-capability jump (Terminal Bench 2.1, DeepSWE) and community quantizations already running on a single RTX 4090 or a 128GB Mac; Alibaba shipped Qwen 3.8 (a 27B local variant and a Max frontier variant) (@simonw); and MiniMax H3 became the first open model to top an AI video ranking, with 33B weights on Hugging Face (The Decoder).
· AI & Model Security
in Attackers Seize N-central RMM Servers After N-able's Second Fix Falls Short
July 26, 2026
in Hotel Wi-Fi Becomes an MFA-Bypass Machine for M365 Accounts
July 20, 2026
- Alibaba released open-weight Qwen 3.8 (2.4T-parameter multimodal), claiming it trails only Fable 5, days after Moonshot's Kimi K3 topped the Code Arena frontend rankings and forced Moonshot to suspend new subscriptions amid demand. Kimi still scores ~39% on FrontierMath Tier 4 versus ~90% for OpenAI/Anthropic, underlining an uneven capability profile (The Decoder — Qwen, The Decoder — Kimi) (discussion).
· AI & Model Security
in AI Moves From Threat Model to Threat Actor: Autonomous Intrusions and a Shrinking Cyber Gap
June 25, 2026
- Anthropic alleges Alibaba illicitly extracted capabilities from Claude, raising the prospect of model-distillation/IP-theft as a recurring dispute between frontier labs. Reuters
· AI & Model Security
in Cisco SD-WAN Manager Zero-Day Gives Root via a Malicious CSV as Operation Endgame Smashes Amadey and StealC