• FluTrackers.com Inc. does not provide medical advice. Information on this web site is collected from various internet resources, and the FluTrackers board of directors makes no warranty to the safety, efficacy, correctness or completeness of the information posted on this site by any author or poster. The information collated here is for instructional and/or discussion purposes only and is NOT intended to diagnose or treat any disease, illness, or other medical condition. Every individual reader or poster should seek advice from their personal physician/healthcare practitioner before considering or using any interventions that are discussed on this website. By continuing to access this website you agree to consult your personal physican before using any interventions posted on this website, and you agree to hold harmless FluTrackers.com Inc., the board of directors, the members, and all authors and posters for any effects from use of any medication, supplement, vitamin or other substance, device, intervention, etc. mentioned in posts on this website, or other internet venues referenced in posts on this website.
  • We are not asking for any donations. Do not donate to any entity who says they are raising funds for us.

Cyber Incidents USA 2026-27

Video​

Mullin warns terrorists, cartels are joining forces against US​

September 6, 2026
Homeland Security Secretary Markwayne Mullin joins 'The Sunday Briefing' to discuss border security, drug cartel drone activity and cyber threats. He also details President Donald Trump's border enforcement policies.

Homeland Security Secretary Markwayne Mullin joins 'The Sunday Briefing' to outline federal efforts against Mexican cartel alliances, evolving drone and foreign cyber threats and calls by progressive lawmakers to reduce funding for border enforcement agencies.

 

China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies​

Release Date September 08, 2026
Alert Code AA26-251A

Executive summary

China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) (hereafter referred to as the authoring agencies) are releasing this joint Cybersecurity Advisory to alert organizations about these malicious activities and techniques and recommend mitigations to reduce their potential impact.

Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024. DeepSeek has conducted organized campaigns since at least 2024 targeting reasoning capabilities, specialized optimizations, and domain-specific functions to train its R1 and V3 models. Alibaba leveraged industrial-scale distillation to improve the company’s Qwen family of AI models. Moonshot AI, MiniMax, Stepfun, and Z.AI also engaged in malicious knowledge distillation of U.S. AI companies’ models.

China-based AI companies route distillation requests through multiple pathways to gain unauthorized access, consequently violating U.S. AI companies’ terms of use. These pathways include native application programming interfaces (APIs), remote cloud providers, and third-party aggregators that automatically obfuscate user metadata to avoid detection. Further, China-based AI companies use a gray market of proxies known as “transfer stations” to bypass U.S. AI companies’ geographic restrictions, breach terms of use, evade safeguards, and undermine traceability. China-based AI companies achieve cost savings for their industrial-scale distillation campaigns through bulk procurement of the U.S. AI companies’ premium subscriptions shared across teams of developers. Advanced industrial-scale distillation tactics include chain-of-thought (CoT) reasoning extraction, automated failover between pathways during blocking attempts, and sophisticated quality evaluation frameworks to detect defensive countermeasures. China-based AI companies that conduct industrial-scale distillation against U.S. AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model.

China-based AI companies deliberately distribute operations across multiple providers, platforms, and pathways to avoid single-point detection. They also attempt to distill the best capabilities and proprietary features of each U.S. frontier model to train their China-based AI models. This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership. Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations.

The authoring agencies recommend U.S. AI companies take three immediate actions:

  1. Implement comprehensive detection and mitigation: Detect anomalous and malicious prompts, accounts, networks, and behaviors. Additionally, monitor subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns.
  2. Deploy targeted response changes: Subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs to companies conducting industrial-scale distillation campaigns.
  3. Establish cross-organization intelligence sharing: Correlate activity across model providers, cloud platforms, and API aggregators to reveal distributed campaigns.

Attribution

continued: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a
 
MA
Springfield schools closed again Wednesday following severe cyber attack
September 08, 2026

Students in Springfield will be out of school again tomorrow after a cyber incident over the long weekend.

The superintendent says the breach interrupted systems necessary for school operations, so schools were closed Tuesday and will be again on Wednesday.

Springfield Public Schools says an outside group gained access to the SPS network and blocked the district’s ability to access certain online programs necessary to operate schools effectively.

Federal, state, and local law enforcement are helping investigate what the school system is calling a severe incident.

Continued: https://www.boston25news.com/news/l...vere-cyber-attack/M2FBILZS5RC2PACJKXPMF4NZHM/
 

FBI – Federal Bureau of Investigation

22h ·
Today at the 17th Annual Billington CyberSecurity Summit, FBI Cyber Deputy Assistant Director Jason Bilnoski highlighted how the #FBI is working with industry as a true operational partner in the cyber fight.
Behind many of the FBI’s most significant cyber operations are industry partners whose intelligence, technical expertise, and operational coordination make successful outcomes possible.
As a recent example, DAD Bilnoski cited last week’s disruption of the Sality botnet, which had been enabling cryptocurrency theft and cyberattacks against victims in the United States and abroad. Close coordination with industry partners was central to that operation and underscores the growing impact of public-private collaboration in confronting cybercriminals.

 

CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats​

New Resources Help Organizations Assess and Mitigate the Challenges and Growing Impact of Insider Threats
Released September 09, 2026

WASHINGTON – The Cybersecurity and Infrastructure Security Agency (CISA) released today the updated Insider Threat Mitigation Guide which provides security support consistent with our statutory mission. The guide gives organizations a current look at insider threats and practical steps to develop or enhance an insider threat program. Delivered in a more streamlined format, the updated guide addresses evolving considerations such as the rise in hybrid and remote work, and advances in artificial intelligence (AI).

First published in 2020, the Insider Threat Mitigation Guide supports security and human resource professionals who manage insider threat programs, as well as leaders at every level of an organization. The guide was updated to acknowledge the growing impact insider threats have on critical infrastructure, the dynamic and evolving operational landscape, and provide new use cases to help organizations address new challenges. Any organization, regardless of the maturity level of its security, can leverage the guide to bolster their threat mitigation program.

“Insider threats continue to evolve as technology becomes more advanced. We urge organizations to establish a mitigation program that protects key assets, prevent violence, reduce losses, safeguard sensitive data, and save lives,” said Acting Executive Assistant Director for Infrastructure Security Scott Breor. “CISA appreciates the industry and government partner feedback that informed this timely update. CISA encourages organizations to review this updated guide, assess their program, and recommended steps to bolster their threat mitigation program.”

This updated guide gives employees an understanding of behavioral indicators that may signal a risk. Key updates in the guide include:
  • New case studies, statistics, and section consolidation designed to enhance the original content, streamline information delivery, and ensure continued relevance.
  • Expanded insights on emerging workplace trends such as increased hybrid and remote work, AI used to manipulate or deceive, and new content on access control, visitor screening, and mitigating the risk of adverse employee separations.
  • Access to newly released CISA resources supporting preparedness and early risk detection.
For more information, please visit Insider Threat Mitigation Resources and Tools.

 

(TLP:CLEAR) NSA Releases Best Practices Guide for Cyber Hygiene to Counter AI-Enhanced Targeting​

TLP:CLEAR
Author: Chase Snow
Created: Thursday, September 10, 2026 - 14:53

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

Summary: On September 3, 2026, the NSA released a Cybersecurity Information Sheet (CSI), “Best Practices Guide for Cyber Hygiene,” addressing how adversaries increasingly use AI to automate the intrusion lifecycle and exploit poor cyber hygiene such as unpatched systems, weak authentication, and misconfigurations. The guide prioritizes mitigations by effectiveness and organizes them into progressive maturity tiers, starting with Tier 0 immediate actions like network inventory, phishing-resistant MFA, and patching, then building toward Zero Trust practices, such as segmentation and continuous monitoring. NSA notes the mitigations were validated against AI-generated exploitation plans and AI-identified vulnerabilities.

Continued: https://www.waterisac.org/tlpclear-...yber-hygiene-to-counter-ai-enhanced-targeting
 

Detecting and countering misuse of AI: September 2026​



Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity. In this report, we share case studies from those operations and describe how malicious use of Claude has evolved since our previous threat reports in March, August, and November 2025. In each case, we disrupted the activity, used what we learned to strengthen our safeguards, and shared intelligence with authorities and industry partners, where appropriate.

This report covers activity we disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Claude Haiku, Sonnet, and Opus models were used. None of the misuse cases involved the use of Claude Fable or Mythos-class models, with the exception of one illicit distillation case.

The cases we share here aren’t typical misuse, but rather examples of the most notable and novel threat activity we’ve identified to date. We’re publishing this work because we believe we have a responsibility to disclose malicious misuse of our services. As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer.

The threat actors covered in this report include suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals. The cases range from a network of fake dating apps designed to defraud users to surveillance systems built to identify and monitor dissidents.

Sophisticated and persistent threat actors continuously test our safeguards and try to circumvent the technical measures we use to detect and prevent misuse. We’ll continue to evolve our safeguards and coordinate with our partners to improve our ability to detect, disrupt, and prevent future misuse.

We hope that the findings in this report will help other developers recognize similar patterns on their own platforms, give governments and civil society a clearer view of how emerging threats take shape, and strengthen collective defenses.

  • GTG-20006: Russian espionage
  • GTG-50014: ShinyHunters smash-and-grab opportunists
  • GTG-10007: Exploit foundries and autonomous attack frameworks
  • AI supply chain as target, loot, and attack compute
  • GTG-50020: From hotel bookings to the AI supply chain
  • GTG-50029: Hacktivists targeted European political and affiliated entities
  • Prevailing trends

AI-augmented cyber operations​

Cyber operations: From assistant to orchestrator​

Over the past six months, our Threat Intelligence team identified and disrupted a series of cyber operations in which threat actors used Claude. The actors included suspected state-sponsored groups, financially motivated criminals, and politically motivated individuals. This section presents some of those cases.

Throughout these case studies, the report will reference Generative Threat Groups (GTGs). These are Anthropic’s internal designators for actors observed to be abusing AI. The report also attempts to measure uplift, a term we use to describe the AI capability boost, or how much more harm was caused with AI versus without AI. We view uplift through the lens of speed, scale, and depth, and attempt to determine how an actor’s adoption of AI meaningfully impacts each of these traits.

Many commentators focus on the risk of AI developing exploits at scale. While this is a danger, the risk from AI adoption is more pronounced across the cyber kill chain, where adversaries can operate faster, across a broader and deeper surface area, with fewer resources.

The cases span the period from December 2025 through August 2026. In all cases, Claude Haiku, Sonnet, and Opus models were used; no malicious activity was found on Claude Fable or Mythos (which has a series of safeguards in place that greatly reduce its ability to perform harmful cyber tasks). In each case we disrupted the activity involved, strengthened our AI safeguards based on what we learned, and shared intelligence with authorities and industry partners where appropriate.

In the following report, we begin by discussing the key trends that we’ve observed in these cyber operations, then move to reporting the case studies and how they highlight those trends.

Trends​

Sophisticated attacks no longer require sophisticated attackers​

The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators. In the case studies we report below, a hacktivist using stolen API keys, disparate financially motivated individuals, and a state espionage operator each sustained multi-victim campaigns that, even just a year ago, would have required many skilled operators and specialist knowledge.

For threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation. Every layer of offensive operations has been uplifted by AI, from reconnaissance and tool development to data processing and exploitation. An example of this uplift in capabilities is documented in case study GTG-50014 (described below). The net effect of this uplift in capabilities is access to an increased breadth and depth of knowledge, which in turn drives increased speed of capability development and implementation.

more.... https://www.anthropic.com/threat-intelligence-report-september-2026
 
Back
Top Bottom