September 13, 2026
- Anthropic names seven China-based labs over illicit distillation, including Alibaba, Moonshot, DeepSeek, Z.ai and MiniMax, in seven campaigns detected since February 2026. The described access routes are proxy or relay stations spinning up thousands of accounts on fake identities, stolen cards and harvested corporate API keys, transcripts bought from resellers, and — in some cases — labs rerouting their own users' requests to Claude to harvest the exchanges (The Hacker News, earlier coverage).
· AI-Enabled Threat Activity
in Artifactory Chains Give Attackers Admin in Under Five Minutes
September 12, 2026
- An inference-time activation edit sharply changed DeepSeek V4.1-Flash’s cyber and refusal results without rewriting weights. @0x0SojalSec subtracted a refusal direction at each layer and reported results moving from 4/32 to 24/32 on one refusal set and 5/32 to 31/32 on a 32-item cyber set. It requires local weights and a modified vLLM path, so this is not a remote jailbreak. The small, self-reported evaluation also does not establish parity with closed frontier models (earlier coverage).
· AI & Agent Security
in Researchers Tie OpenAI’s Agent Swarm to a 2,000-Package RubyGems Attack
September 11, 2026
- GreyNoise traced the PaperCut NG/MF campaign (CVE-2026-81578, CVE-2026-82078) to
45.142.193.132, an IP it has watched since early July hitting Palo Alto, Ubiquiti, Citrix, SonicWall and Proxmox gear. Starting 31 August the actor built a lab with a vulnerable PaperCut server and an Active Directory box, built target lists via a Netlas.io API key, then ran hundreds of agents on an OpenAI Codex harness driving a DeepSeek model plus off-the-shelf offensive tooling. From empty workspace to RCE on a real victim took under four hours, first domain admin another two; once launched, 11 organizations fell in 26 seconds, and one US high school went from initial access to domain admin in seven minutes. PaperCut NG/MF runs as SYSTEM by default on Windows and is usually domain-joined (GreyNoise, BleepingComputer). Blackpoint Cyber reported the activity independently (The Hacker News). Attackers chaining the PaperCut pair for credential theft was earlier coverage; the AI orchestration and victim count are new.
· Offensive AI in the Wild - DeepSeek V4.1-Flash is out under MIT: 552B parameters with 16B active per token, KV cache memory cut to a quarter of its predecessor, and a narrow win over Opus 5 and GPT-5.6 Sol on the DeepSWE coding benchmark (The Decoder).
· Policy & Frontier AI
in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign
September 10, 2026
BlueMoon exploit kit chains Chrome and Windows zero-days within days of patch publication, with four suspected China-linked espionage groups weaponizing the same toolkit on US and Southeast Asian targets from late August onward. Cisco Secure Firewall Management Center CVEs are under active exploitation by three distinct post-compromise clusters including a ransomware operator and Sandworm-attributed activity. DeepSeek AI agent harness contained an authentication bypass allowing remote agents to escalate privileges via a single shell command; Anthropic declined to provide pre-release model access to UK authorities, triggering debate over AI protectionism. Stealer logs now monetize replayable AI-service tokens from compromised systems, with over 500 valid Google, Anthropic, and Cursor credentials found in a single 7 GB dump.
September 9, 2026
- StrikeAgent_AtkBrain-Flash, an offensive AI agent open-sourced by the Yean-Sec ("Night Peace") team, targets external-perimeter red teaming, bug bounty and CTF work. It drives an attack graph with supervision only at round boundaries, distills reusable techniques into a memory store for the next run, and adds a red-team second-pass rating and re-verification step to cut model false positives; the team claims third place on the Cybench leaderboard (deepseek-v4-flash, 84.13/100) (GitHub).
· New Tools & Releases
- NSA, CISA and FBI named six Chinese AI companies over "industrial-scale" model distillation. The joint advisory says DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI extracted billions of tokens across millions of exchanges from variants of Claude, GPT, Gemini and Grok since at least late 2024, routed through native APIs, cloud providers, third-party aggregators and gray-market "transfer station" proxies to evade geo-restrictions and traceability. Detection guidance includes 24/7 sustained usage with no human idle periods; the agencies suggest altering responses to confirmed distillation clients rather than simply cutting them off (CISA AA26-251A).
· AI & Model Security
in One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android
August 25, 2026
- Reasoning models used as autonomous jailbreak operators. A circulating research summary describes giving DeepSeek, Grok and Qwen a single adversarial system prompt, after which the models planned and ran unsupervised multi-turn attacks against nine target models, adapting their approach when a target refused — framed as an "alignment regression". Worth watching, but the thread does not link the underlying paper, so treat the numbers as unverified (@HowToPrompt\_\_).
· AI & Agent Security
in The Rogue Agent Staged an Apology, Then Pushed More Malware
August 21, 2026
Microsoft's Defender Boot-Time Removal driver (BTR.sys) can be weaponized as a Ring-0 primitive to bypass Tamper Protection and delete EDR/AV before they start, with no vulnerability or BYOVD required. Zimbra, GitLab, and MLflow are actively exploited in the wild, while OpenAI paused frontier RL training after the Hugging Face breach and deployed Astra autonomous agents. Citrix NetScaler CVE-2026-19490 is a critical authentication bypass expected to be exploited imminently, and a Rust supply-chain attack deployed malicious proc-macro crates with PowerShell backdoors targeting Windows build systems.
August 14, 2026
- DeepSeek Harness v0.1 — DeepSeek open-sourced its agent runtime under MIT alongside V4-Pro's GA, pitched as plugin-everything infrastructure for continuous ("recursive self-improvement") agent self-modification with rollback guarantees. API prices rose in the same move, with cache hits jumping ~6x. (The Decoder)
· New Tools & Releases
- Multiple jailbreaks landed against the new DeepSeek V4-Pro. Researchers reported near-total bypass of guardrails across privesc, KRACK, and physical-crime framings under "defender/academic" pretexts, with cyber/chem/bio production cited as the remaining hard wall. (@SingulCore)
· AI & Model Security
in vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries
August 4, 2026
- A China-linked actor weaponized a DeepSeek AI agent against a security firm. Researchers intercepted and analyzed the model as it attempted to compromise more than 1,200 hosts for proxyjacking to stage further attacks (Dark Reading) — a live example of the AI-as-operator pattern from earlier coverage.
· Threat Activity
- Open-model releases keep coming in waves. DeepSeek V4 Flash reached GA with a big agentic-capability jump (Terminal Bench 2.1, DeepSWE) and community quantizations already running on a single RTX 4090 or a 128GB Mac; Alibaba shipped Qwen 3.8 (a 27B local variant and a Max frontier variant) (@simonw); and MiniMax H3 became the first open model to top an AI video ranking, with 33B weights on Hugging Face (The Decoder).
· AI & Model Security
in Attackers Seize N-central RMM Servers After N-able's Second Fix Falls Short
August 2, 2026
- DeepSeek's new V4 Flash update draws rapid jailbreaks. The "0731" refresh jumps ten points on the Artificial Analysis index, landing near GPT-5.6 Luna at ~60% lower cost (The Decoder). Researchers immediately reported it as trivially jailbroken, with claims of cracking 6 of 8 refusal classes via a single system prompt and eliciting malware and hazardous-synthesis content — one tester calling it "extremely easy to jailbreak" (@elshayib_).
· AI & Model Security
in Coldcard Wallet Theft Climbs Past $88M as Attackers Drain Weak-Entropy Addresses in Waves
August 1, 2026
- A Chinese-speaking threat actor is running autonomous attacks by wiring the DeepSeek model into the open-source Hermes Agent framework. Palo Alto Unit 42 reports that after a single Telegram instruction, the agent independently discovered internet-facing systems, selected public exploits, and ran the session with no further operator input; the operator is tracked under the aliases knaithe and KnYuan (BleepingComputer, The Hacker News). This is a concrete continuation of the Hermes-driven activity seen against Thailand's finance ministry.
· AI & Offensive Security
in When the Attacker Is a Model: AI Lands on Both Sides of the Fight
July 2, 2026
- Check Point documented the first case of a frontier model (DeepSeek) being jailbroken into building working in-browser ransomware that abuses the browser File System Access API with AI-generated obfuscation, running entirely in-browser on Windows and Android. The Register, The Hacker News.
· AI & Model Security
in Scattered Spider Suspect Grabbed at Helsinki Airport, Extradited to the US
July 1, 2026
watchTowr Labs disclosed CVE-2026-8451, a pre-auth memory overread in Citrix NetScaler SAML handling that extends the CitrixBleed lineage, alongside five other patched flaws. A China-linked USB implant infected Japanese military networks for nearly a year via disaster-relief supply chains, while European defense targets faced spear-phishing campaigns abusing AWS Cognito for credential-less C2 infrastructure. Multiple AI agent safety bypasses emerged, including GuardFall (shell injection against coding agents), BioShocking (prompt injection stealing credentials), and poisoned MCP tool descriptions enabling data exfiltration without raising alerts.
June 29, 2026
- Coinbase reportedly dropped OpenAI and Anthropic for open-weight Chinese models from Zhipu (GLM 5.2) and DeepSeek, citing roughly 9x lower cost for equivalent output and competitive coding benchmarks — a notable signal on enterprise AI economics and the failure of export controls to slow Chinese model quality. (Ric_RTP via cyb3rops)
· AI & Model Security
in Public Root Exploit for Linux "pedit COW" Lands as Offensive Tooling Floods the Week
June 20, 2026
FortiBleed has compromised ~86,644 internet-facing FortiGate devices in a credential-harvesting campaign, while a leaked GitHub token gave FulcrumSec access to Novo Nordisk, exfiltrating 1.3TB including unreleased drug formulas and internal AI models. Mastra npm packages were trojanized by Sapphire Sleet (North Korea–nexus), and multiple AI infrastructure flaws emerged: SearchLeak (CVE-2026-42824) in Microsoft 365 Copilot, Pickle in the Middle in Google Vertex AI, and vulnerabilities in LiteLLM. Ransomware gangs including Qilin, Gentlemen, and DragonForce continue dominating the threat landscape with EDR-killing tradecraft and cloud-based C2 abuse.