September 14, 2026
- The NSA is replacing its directorate structure with five mission centers. The Record reports, based on multiple current and former officials, that centers for China, cybersecurity, artificial intelligence, combat support, and global intelligence are being created in the agency’s largest reorganization in roughly a decade. Director Joshua Rudd started a 30-day implementation clock earlier this month, with full operational capability targeted for January 2027. Tailored Access Operations is expected to sit under global intelligence, but the placement of the Cybersecurity Collaboration Center and the future division of labor with U.S. Cyber Command remain unresolved.
· Cyber Operations & Policy
in Hermes Logs Reveal Unattended AI Post-Exploitation
September 9, 2026
- NSA, CISA and FBI named six Chinese AI companies over "industrial-scale" model distillation. The joint advisory says DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI extracted billions of tokens across millions of exchanges from variants of Claude, GPT, Gemini and Grok since at least late 2024, routed through native APIs, cloud providers, third-party aggregators and gray-market "transfer station" proxies to evade geo-restrictions and traceability. Detection guidance includes 24/7 sustained usage with no human idle periods; the agencies suggest altering responses to confirmed distillation clients rather than simply cutting them off (CISA AA26-251A).
· AI & Model Security
in One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android
August 20, 2026
- NSA, FBI and CISA say attackers are using AI to generate exploit scripts against Siemens S7-series PLCs, combining AI-assisted development with exploitation of known ICS vulnerabilities. Agencies stress this is "not a theoretical risk," and the framing matters for defenders: the interesting claim isn't novel capability but collapsed time-and-skill cost for attacking industrial controllers in energy, water, and manufacturing (The Record, BleepingComputer, The Register).
· Critical Infrastructure & AI-Assisted Offense
in Feds Say AI-Written Exploit Code Is Already Hitting Siemens PLCs