❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdaySecurity/Privacy

Feds accuse China of ‘systematic’ distillation of U.S. AI models

By: djohnson
8 September 2026 at 16:47

 The U.S. government is accusing Chinese AI companies of engaging in a deliberate and “systematic” effort to illegally distill U.S. frontier AI models and their capabilities. 

According to a joint cybersecurity advisory from the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI, the sheer scale of these efforts since 2024 indicate that distillation is a critical part of China’s AI industrial policy.

“China-based artificial intelligence companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy,” the agencies wrote. 

The advisory names Chinese companies like DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, saying they spent billions of tokens across millions of exchanges and requests with frontier U.S. AI models like Anthropic’s Claude, OpenAI’s ChatGPT, Google Gemini, and xAI’s Grok, since at least late 2024.

The U.S. agencies said the companies used data culled from these interactions to strengthen their own domestic models, a practice that is tacitly encouraged but not directed by political leaders in Beijing.

DeepSeek, for example, distilled frontier U.S. models to generate synthetic training data for its R1 and R3 models, including four different versions of Claude, two versions of Gemini, five versions of ChatGPT and Grok 4. Those models helped train DeepSeek’s capabilities in areas like agentic functioning, question and answer optimization, creative and occupational writing and others.

Another Chinese company, Moonshot AI, allegedly distilled 18 different U.S. models – including Fable 5, Anthropic’s current, most advanced commercially available model – to train its Kimi-K2 and Kimi K3 models. The company used millions of queries meant to extract enhanced capabilities in areas like agentic reasoning, coding and data analysis, computer vision, larger logical frameworks, visual processing and others.

Chinese AI companies manage a sophisticated set of tools and systems that route requests and prompts through multiple pathways to avoid detection.

The advisory lists common tactics observed by Chinese companies, including spreading requests across different accounts, models and platforms, using native APIs, remote cloud providers, and third-party aggregators to obfuscate user metadata, and leveraging proxies and gray tech markets to get around geographic restrictions, terms of use and safeguards built into frontier models.

“Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations,” the advisory stated.

For decades, U.S. national security officials and western business leaders have accused China of leveraging cyberattacks, insider threats and other forms of economic espionage to pilfer proprietary or sensitive technologies from U.S. businesses.

In June, Michael Kratsios, White House head of Office of Science and Technology Policy, made a similar accusation about MoonshotAI of distilling Fable 5 to train its own models, and described a similar “sophisticated” system for evading guardrails and restrictions on usage.

The warning Tuesday levies similar charges about Chinese theft of American tech, but for frontier AI companies that are facing lawsuits themselves from artists, authors, media organizations and other parties who say AI companies illegally trained their models on copyrighted or trademarked work.

Even within the competitive AI industry, companies and open-source organizations commonly share weights and measures for AI systems, or distill other AI systems in the course of legitimate work or research.

The agencies acknowledge this reality, but claim that Chinese companies are engaged in “aggressive, malicious, and targeted distillation activities at an industrial scale.”

The post Feds accuse China of ‘systematic’ distillation of U.S. AI models appeared first on CyberScoop.

Why federal cyber defense demands an offense-driven mindset

8 September 2026 at 14:30

Federal agencies are drowning in cybersecurity data. Every day, security operations centers absorb millions of logs, scanner alerts and inventory feeds. But raw, static data isn’t actionable intelligence. Ask a room of federal CISOs to name the three critical weaknesses an adversary could exploit today to compromise their missions, and you’ll likely be met with a mountain of compliance reports.

That disconnect reveals a critical velocity problem in government risk management.      Traditional vulnerability management treats every Common Vulnerabilities and Exposures (CVE) entry and high Common Vulnerability Scoring System (CVSS) score as an equal emergency, regardless of whether it’s actually exploitable. Security teams spend weeks chasing theoretical findings, while adversaries exploit overlooked attack paths in hours. CVSS scores are static abstractions: they cannot reveal whether a flaw is reachable today, chainable with other weaknesses or capable of causing immediate mission damage.

As AI collapses the window between vulnerability disclosure and exploit execution, CISA’s issuance of BOD 26-04 marks a long-overdue pivot. The directive codifies what frontline defenders already know: agencies cannot win 90-day patch races against adversaries moving at machine speed. Federal cyber defense must shift from reactive spreadsheet patching to real-time prioritization based on exploitability, active threats and mission risk.

Vulnerable does not mean exploitable

During 30 years in IT operations and military cyber environments, I lost count of how many times I had to tell an auditor: “That high-severity CVE is a false positive, the vulnerable module isn’t running, or we’ve mitigated it six different ways.”

That gap between vulnerable and exploitable is where federal security teams lose the clock. Vulnerability scanners produce thousand-page laundry lists. Teams work from the top down, spending finite engineering hours patching high-severity “purples.” They often exhaust their time and budget before reaching the medium- and low-severity findings.

Adversaries do not follow a 90-day patch cycle. Attackers rarely burn a valuable zero-day exploit when a misconfiguration, weak trust relationship or stolen credential provides a direct path to their objective. As my colleague Todd Beebe from Freeport LNG has noted, “Credentials are the everyday zero-day.” Attackers don’t hack in when they can simply log in.

Defenders spend months building fortresses around static “crown jewel” systems while adversaries maneuver around those controls by chaining low-severity weaknesses with compromised identities. CVEs are only part of the story: misconfigurations and the tactics, techniques and procedures that live between CVEs matter just as much. We’ve validated thousands of attack paths across thousands of organizations that led to critical impact without leveraging a single CVE, and the only way to understand those paths is through offense-driven defense. Closing a vulnerability ticket on schedule doesn’t mean you have stopped an attacker. Untested assumptions are what get organizations in the news.

The cyber version of the McNamara Fallacy

Federal leaders risk falling victim to a modern cyber version of the McNamara Fallacy. Named for Defense Secretary Robert McNamara’s reliance on quantifiable metrics during the Vietnam War, it describes managing by what is easiest to count (e.g., patches applied, tickets closed and average CVSS scores) while overlooking operational reality.

I learned this lesson firsthand while leading IT and cybersecurity operations for a specialized defense unit. Our team was compliant. We checked every DISA STIG box, passed every audit and maintained immaculate documentation. Then a red team assessed our environment. Across people, process and technology, our organization performed well, but the assessment still found things a threat actor could immediately take advantage of.

When I asked whether they could return in three months to verify our fixes, they laughed. “No way,” they said. “You don’t have the budget, and we don’t have the resources.”

That experience fundamentally shifted my mindset: it is much easier to be compliant than secure.

Human-led penetration testing remains valuable, but small-scoped, point-in-time assessments cannot match today’s threat velocity. A manual test conducted annually gives you 24 hours of confidence and 364 days of guesswork. In an AI-accelerated environment, the report may be stale before the ink dries.

Proving defenses work in real time

Across modern framework developments, from NIST SP 800-53 Rev. 5 and NIST CSF 2.0 to federal zero trust mandates, FedRAMP, and Continuous Threat Exposure Management (CTEM), the market is shifting from static attestation toward validation and verification:

  • Compliance asks if a control is present and documented.
  • Validation asks if that control stops realistic attacker behavior now.
  • Verification asks if remediation eliminated the attack path in production.

To outpace adversaries, agencies must augment human expertise with autonomous penetration testing capabilities. We know this works in high-assurance public-sector environments. Under the NSA’s Continuous Autonomous Penetration Testing (CAPT) program, autonomous testing has logged 223,833 hours of operations across 28,282 completed pentests, spanning more than 3.7 million endpoints across 822 Defense Industrial Base organizations.

More importantly, the program accelerated remediation, saving more than 340,000 labor hours and enabling lean security teams to verify and close 71% of critical findings within 30 days. That is the difference between an annual-audit mindset and real-time operational defense.

Three action steps for federal leaders

Federal leaders should take three steps to operate at the speed of the threat:

  1.   Define risk through exploitability and impact. Risk is the product of likelihood and impact. But legacy vulnerability management accepts theoretical guessing of likelihood and fails to account for the consequences of the exploitation. Remediation should prioritize validated attack paths posing immediate mission risk.
  1. Move to continuous verification. In the military, we said, “Trust but verify.” In modern cyber defense, it is simply “verify.” Agencies must safely and continuously test controls, architectures, and identity permissions in production from multiple perspectives, including outside-in, assumed-breach, identity-based, and cloud-native.
  2. Verify the fix, not the activity. A ticket should not close merely because someone deployed a patch or changed a configuration. It should close only after a targeted retest confirms the exploitable attack path is gone.

As Corey Brunkow, Horizon3’s Director of Federal Operations, puts it: “Compliance is the baseline, not the finish line. In the new era of AI-enabled attacks, government and supply chain partners cannot afford to mistake a documented security control for an effective one.” The only way to know whether defenses can withstand an adversary is to send an attacker at them. Federal leaders must turn the map around, view their networks through the eyes of the adversary and continuously validate their security posture before an opponent does.

Learn how Horizon3 can help organizations move from point-in-time compliance to continuous, autonomous penetration testing.

The post Why federal cyber defense demands an offense-driven mindset appeared first on CyberScoop.

The G7 tells industry to hurry up and prep for post-quantum encryption

By: djohnson
3 September 2026 at 15:29

A cybersecurity working group at the G7 is urging governments to accelerate defenses against quantum computers that could break some existing forms of public key encryption.

The working group’s report, prepared in June at the G7 Summit in France, said organizations “can no longer afford to postpone” work transitioning critical systems and data to “post-quantum” forms of encryption.

“The quantum threat remains off the radar for many organizations and not properly resourced, with other security concerns taking precedence,” the working group report said. “Yet, a successful and collective transition to PQC can only be achieved if organizations understand that the quantum threat is an economic and business risk, and not merely a cryptographic risk.”

Instead, leaders in government and industry “must reframe the quantum threat from a distant future problem to a near-term threat that demands action across all sectors, not just critical infrastructure.”

The report acknowledged uncertain timelines for quantum computers, but identified that threats like harvesting current sensitive, encrypted data to decrypt it in the future do exist today.

The report also warned that quantum computers could compromise authentication and assurance mechanisms—by forging trusted data or stealing confirmation— jeopardizing secure communications and legal contracts.

The working group’s conclusions are largely in line with what governments have been recommending for years, urging industry to inventory and prioritize their critical systems and shift over to newer, “post-quantum cryptography” encryption algorithms.

These encryption algorithms, originally designed by independent cryptographers and vetted by the National Institute for Standards and Technology and National Security Agency, will be used to protect the government’s own systems and data from cybercriminals and foreign governments.

The Trump administration recently issued an executive order directing agencies to boost the domestic quantum industry and move up internal timelines for migrating to PQC encryption from 2035 to 2030. Google, a potential industry bellwether, and other companies have opted to move their own migration timelines to 2029.

But while that work has proceeded on schedule in some areas, like the federal government and the highly regulated financial sector, it has lagged in other industries where owners and operators feel they have more immediate concerns than quantum computers.

“We acknowledge that transitioning to PQC is not a problem for individual organizations to solve in isolation, but rather a collective transition that can only be achieved with early engagement, coordinated planning and informed decision making across the public and private sectors,” the working group wrote.

While often referred to as “Post-Quantum” encryption, the reality is more complex. Cryptographers believe the algorithms selected by NIST and NSA will stand up to attacks from a quantum computer, but since one doesn’t exist today, designing cryptographic protections against it requires some guesswork and mathematical estimation.

Estimates can be wrong, or overlook the entire cryptographic attack surface. Some NIST-selected algorithms have already been broken with traditional computers or AI. That’s why the agency backs multiple algorithms and concepts like “crypto-agility,” allowing organizations to quickly switch between them.

The G7 report was signed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the UK’s National Cyber Security Centre (NCSC), The French Cybersecurity Agency (ANSSI), Germany’s Federal Office of Information Security (BSI), Canada’s Communications Security Establishment (CSE), Japan’s National Cybersecurity Office (NCO) and Italy’s National Cybersecurity Agency (ACN).

The post The G7 tells industry to hurry up and prep for post-quantum encryption appeared first on CyberScoop.

Lawrence’s List 070116

By: BHIS
1 July 2016 at 11:20

Lawrence Hoffman // As I previously mentioned I’m on vacation this week and next. As I like to go for long cross-country drives I’ve not had much time to keep […]

The post Lawrence’s List 070116 appeared first on Black Hills Information Security, Inc..

❌
❌