• FluTrackers.com Inc. does not provide medical advice. Information on this web site is collected from various internet resources, and the FluTrackers board of directors makes no warranty to the safety, efficacy, correctness or completeness of the information posted on this site by any author or poster. The information collated here is for instructional and/or discussion purposes only and is NOT intended to diagnose or treat any disease, illness, or other medical condition. Every individual reader or poster should seek advice from their personal physician/healthcare practitioner before considering or using any interventions that are discussed on this website. By continuing to access this website you agree to consult your personal physican before using any interventions posted on this website, and you agree to hold harmless FluTrackers.com Inc., the board of directors, the members, and all authors and posters for any effects from use of any medication, supplement, vitamin or other substance, device, intervention, etc. mentioned in posts on this website, or other internet venues referenced in posts on this website.
  • We are not asking for any donations. Do not donate to any entity who says they are raising funds for us.

Cyber Incidents USA 2026-27

Video​

Mullin warns terrorists, cartels are joining forces against US​

September 6, 2026
Homeland Security Secretary Markwayne Mullin joins 'The Sunday Briefing' to discuss border security, drug cartel drone activity and cyber threats. He also details President Donald Trump's border enforcement policies.

Homeland Security Secretary Markwayne Mullin joins 'The Sunday Briefing' to outline federal efforts against Mexican cartel alliances, evolving drone and foreign cyber threats and calls by progressive lawmakers to reduce funding for border enforcement agencies.

 

China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies​

Release Date September 08, 2026
Alert Code AA26-251A

Executive summary

China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) (hereafter referred to as the authoring agencies) are releasing this joint Cybersecurity Advisory to alert organizations about these malicious activities and techniques and recommend mitigations to reduce their potential impact.

Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024. DeepSeek has conducted organized campaigns since at least 2024 targeting reasoning capabilities, specialized optimizations, and domain-specific functions to train its R1 and V3 models. Alibaba leveraged industrial-scale distillation to improve the company’s Qwen family of AI models. Moonshot AI, MiniMax, Stepfun, and Z.AI also engaged in malicious knowledge distillation of U.S. AI companies’ models.

China-based AI companies route distillation requests through multiple pathways to gain unauthorized access, consequently violating U.S. AI companies’ terms of use. These pathways include native application programming interfaces (APIs), remote cloud providers, and third-party aggregators that automatically obfuscate user metadata to avoid detection. Further, China-based AI companies use a gray market of proxies known as “transfer stations” to bypass U.S. AI companies’ geographic restrictions, breach terms of use, evade safeguards, and undermine traceability. China-based AI companies achieve cost savings for their industrial-scale distillation campaigns through bulk procurement of the U.S. AI companies’ premium subscriptions shared across teams of developers. Advanced industrial-scale distillation tactics include chain-of-thought (CoT) reasoning extraction, automated failover between pathways during blocking attempts, and sophisticated quality evaluation frameworks to detect defensive countermeasures. China-based AI companies that conduct industrial-scale distillation against U.S. AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model.

China-based AI companies deliberately distribute operations across multiple providers, platforms, and pathways to avoid single-point detection. They also attempt to distill the best capabilities and proprietary features of each U.S. frontier model to train their China-based AI models. This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership. Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations.

The authoring agencies recommend U.S. AI companies take three immediate actions:

  1. Implement comprehensive detection and mitigation: Detect anomalous and malicious prompts, accounts, networks, and behaviors. Additionally, monitor subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns.
  2. Deploy targeted response changes: Subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs to companies conducting industrial-scale distillation campaigns.
  3. Establish cross-organization intelligence sharing: Correlate activity across model providers, cloud platforms, and API aggregators to reveal distributed campaigns.

Attribution

continued: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a
 
MA
Springfield schools closed again Wednesday following severe cyber attack
September 08, 2026

Students in Springfield will be out of school again tomorrow after a cyber incident over the long weekend.

The superintendent says the breach interrupted systems necessary for school operations, so schools were closed Tuesday and will be again on Wednesday.

Springfield Public Schools says an outside group gained access to the SPS network and blocked the district’s ability to access certain online programs necessary to operate schools effectively.

Federal, state, and local law enforcement are helping investigate what the school system is calling a severe incident.

Continued: https://www.boston25news.com/news/l...vere-cyber-attack/M2FBILZS5RC2PACJKXPMF4NZHM/
 

FBI – Federal Bureau of Investigation

22h ·
Today at the 17th Annual Billington CyberSecurity Summit, FBI Cyber Deputy Assistant Director Jason Bilnoski highlighted how the #FBI is working with industry as a true operational partner in the cyber fight.
Behind many of the FBI’s most significant cyber operations are industry partners whose intelligence, technical expertise, and operational coordination make successful outcomes possible.
As a recent example, DAD Bilnoski cited last week’s disruption of the Sality botnet, which had been enabling cryptocurrency theft and cyberattacks against victims in the United States and abroad. Close coordination with industry partners was central to that operation and underscores the growing impact of public-private collaboration in confronting cybercriminals.

 

CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats​

New Resources Help Organizations Assess and Mitigate the Challenges and Growing Impact of Insider Threats
Released September 09, 2026

WASHINGTON – The Cybersecurity and Infrastructure Security Agency (CISA) released today the updated Insider Threat Mitigation Guide which provides security support consistent with our statutory mission. The guide gives organizations a current look at insider threats and practical steps to develop or enhance an insider threat program. Delivered in a more streamlined format, the updated guide addresses evolving considerations such as the rise in hybrid and remote work, and advances in artificial intelligence (AI).

First published in 2020, the Insider Threat Mitigation Guide supports security and human resource professionals who manage insider threat programs, as well as leaders at every level of an organization. The guide was updated to acknowledge the growing impact insider threats have on critical infrastructure, the dynamic and evolving operational landscape, and provide new use cases to help organizations address new challenges. Any organization, regardless of the maturity level of its security, can leverage the guide to bolster their threat mitigation program.

“Insider threats continue to evolve as technology becomes more advanced. We urge organizations to establish a mitigation program that protects key assets, prevent violence, reduce losses, safeguard sensitive data, and save lives,” said Acting Executive Assistant Director for Infrastructure Security Scott Breor. “CISA appreciates the industry and government partner feedback that informed this timely update. CISA encourages organizations to review this updated guide, assess their program, and recommended steps to bolster their threat mitigation program.”

This updated guide gives employees an understanding of behavioral indicators that may signal a risk. Key updates in the guide include:
  • New case studies, statistics, and section consolidation designed to enhance the original content, streamline information delivery, and ensure continued relevance.
  • Expanded insights on emerging workplace trends such as increased hybrid and remote work, AI used to manipulate or deceive, and new content on access control, visitor screening, and mitigating the risk of adverse employee separations.
  • Access to newly released CISA resources supporting preparedness and early risk detection.
For more information, please visit Insider Threat Mitigation Resources and Tools.

 
Back
Top Bottom