September 9, 2026
- NSA, CISA and FBI named six Chinese AI companies over "industrial-scale" model distillation. The joint advisory says DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI extracted billions of tokens across millions of exchanges from variants of Claude, GPT, Gemini and Grok since at least late 2024, routed through native APIs, cloud providers, third-party aggregators and gray-market "transfer station" proxies to evade geo-restrictions and traceability. Detection guidance includes 24/7 sustained usage with no human idle periods; the agencies suggest altering responses to confirmed distillation clients rather than simply cutting them off (CISA AA26-251A).
· AI & Model Security
in One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android
August 25, 2026
- Reasoning models used as autonomous jailbreak operators. A circulating research summary describes giving DeepSeek, Grok and Qwen a single adversarial system prompt, after which the models planned and ran unsupervised multi-turn attacks against nine target models, adapting their approach when a target refused — framed as an "alignment regression". Worth watching, but the thread does not link the underlying paper, so treat the numbers as unverified (@HowToPrompt\_\_).
· AI & Agent Security
- Cursor shipped its Grok bot (0.18.0) with runtime source maps enabled, making source recoverable at runtime — a reminder that AI dev-tool builds get the same release hygiene as any other Electron app (@thegrugq, relaying @b_nnett).
· AI & Agent Security
in The Rogue Agent Staged an Apology, Then Pushed More Malware
August 22, 2026
- Encrypted prompts bypass safety guardrails in Grok and Gemini, with encoded input surviving filtering long enough to be decoded and acted on downstream (SecurityWeek).
· AI & Model Security
in A CVSS 10.0 Lands in Entra ID — and Microsoft Can't Keep Its Exploitation Story Straight
July 14, 2026
- xAI's Grok Build CLI was uploading entire Git repositories — including private codebases — to a Google Cloud bucket, per researchers who advise anyone who used it to check logs (
~/.grok/logs/unified.json for repo_state.upload). A sharp reminder that AI dev tooling is itself a supply-chain exposure. @Dinosn
· AI & Model Security
in New PoC Spoofs Callstacks Around Intel CET to Blind Modern EDRs