US accuses Chinese AI firms of ‘malicious’ copying at industrial scale
Officials say DeepSeek, Alibaba and four other companies exploited leading American AI models to accelerate development of their own products, escalating tensions ahead of a planned Trump-Xi meeting
The US government accused Chinese artificial intelligence companies of maliciously copying technology from American AI firms, potentially complicating relations ahead of a planned meeting between leaders of the world's two biggest economies later this month.
The Chinese companies copied US AI labs’ intellectual property through a technique known as distillation, according to a statement from US law enforcement and intelligence officials. Distillation is the process of training smaller AI models using output from larger, more expensive ones as part of an effort to lower the costs of training a new AI tool.
US officials accused six Chinese companies, including DeepSeek, Moonshot AI and Alibaba (9988.HK), opens new tab, of tapping variants of American-made AI models to train their AI products more quickly. The companies did so "likely with Chinese government awareness," according to the statement from US officials, who added that the Chinese companies targeted AI models from Anthropic, OpenAI, Alphabet's Google, and SpaceX.
"China-based AI companies are engaging in aggressive, malicious and targeted distillation activities at an industrial scale," the officials said.
The US made the allegations as the administration of President Donald Trump prepares for Chinese President Xi Jinping's visit to the US in late September. The US made a similar accusation in April ahead of Trump's visit to Beijing. (Courtney Rozen and AJ Vicens / Reuters)
Related: The Information, CyberScoop, Wall Street Journal, Business Standard, Modern Diplomacy, Sputnik News, CISA, CoinDesk, Unite.AI, NBC News, Nextgov/FCW, South China Morning Post, IC3
Metacurity is the cybersecurity news, analysis, and insight you'd need hours and possibly days to assemble yourself.
Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.
A paid subscription to Metacurity delivers
- Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
- Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
- Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.
Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.
Please consider supporting us. And thank you!
Jacob Coxon, an Anthropic researcher who specializes in training new AI models by having them consume vast amounts of data, said he is leaving the company because he doesn’t want to participate in an industry-wide rush to build AI systems that can improve themselves, worried such systems could spiral out of control and destroy humanity.
The 27-year-old Brit, who previously studied mathematics, said many of his industry colleagues now use phrases like “crunchtime” and “endgame” to describe the trajectory toward self-improving models.
“We’re on track for a lot of the most aggressive of these scenarios where by the end of next year things could be out of control already,” Coxon said, adding that safety trade-offs are inevitable when companies are competing against one another and Chinese upstarts.
Coxon said he left OpenAI earlier this year to join Anthropic because it is known for its model-safety efforts. But even though he found Anthropic’s safety efforts to be earnest, he now believes no company can responsibly develop AI that can outperform humans in a range of tasks, sometimes called artificial general intelligence, absent government intervention or a coordinated industry slowdown. (Amrith Ramkumar / Wall Street Journal)
Related: CTech, Business Today, Politico, Business Standard, The Economic Times, The Indian Express, Yahoo Finance, Gizmodo, Business Insider, Neowin, Digit, RuntimeWire, VINnews, Moneycontrol, r/politics, r/OpenAI, r/technology, r/artificial, r/antiai, Invezz, TugaTech, Tech - Insider, Tech - Insider, BeInCrypto

A small team of researchers at Calif, a security company based in Palo Alto, Calif., recently built a hacking tool in a little more than a week that could run roughshod across WeChat, potentially compromising hundreds of millions of devices within hours.
The attack is the latest — and one of the most alarming — demonstrations yet of the breakneck speed at which AI is progressing, outpacing the ability of regulators and even of leading developers to keep up.
Calif said the attack, which it named WeWorm, was the first known computer worm — a type of malicious software that can leap from machine to machine on its own absent human help — that could spread across Apple’s iOS and Google’s Android operating systems without needing a victim to click or tap on anything. So-called zero-click attacks are different, and far more lethal, than standard phishing emails and texts. They are considered especially pernicious because they are so hard to defend against, given that they do not require a victim to step into a digital booby trap.
A spokeswoman for Tencent, the Chinese technology company that owns WeChat, confirmed the vulnerability and said that it had fixed the issue after being contacted by Calif. (Dustin Volz / The New York Times)
Related: Calif, International Business Time, Security Affairs, The Hacker News, PCMag, Help Net Security
Researchers at Google Threat Intelligence Group (GTIG) report that hackers working for Chinese intelligence are increasingly targeting American AI research and using AI in their operations.
In its latest quarterly report, GTIG said that several hacker groups, including both intelligence agencies and cybercrime gangs, have moved from basic AI prompting to using AI agents that automate wide swaths of their intrusion.
The switch means hackers spend drastically less time actively hacking, and in some cases can conduct an entire campaign in less than six hours, the report says.
Google said that one Chinese group in particular, called UNC6508, which it has tracked since 2023, has relentlessly focused on academic, medical and military research organizations in North America and has specifically gone after proprietary AI research. Google did not name any of the victims.
Google said it had observed the hacker group compromising unrelated victims’ cloud networks and installing open-source AI models — a way to query models without leaving a trail via commercial AI products.
John Hultquist, the chief analyst at Google’s Threat Intelligence Group, said that running those models on a hacked third-party system allows hackers to avoid monitoring and bypass guardrails that might stop a more popular commercial chatbot from helping with a hacking campaign.
“They compromise a third party and they put models on that third party. They do that instead of using, say, a commercial option where their activities are observed,” Hultquist said.
Google also said that it continues to observe actors leveraging AI to augment various phases of the attack lifecycle, particularly for use cases such as vulnerability research, malware development, and generating information operations (IO) content. (Kevin Collier / NBC News and Google)
Related: Cyber Magazine, Help Net Security, Silicon Angle, Infosecurity Magazine, CTech, The Register

The UK's AI Security Institute (AISI) has not been granted access to Anthropic’s Mythos 5.1 model for pre-release testing, prompting fears of a growing “protectionist” trend among US developers.
The Financial Times reports that Anthropic declined to submit the model for testing despite granting access to similar US organizations.
Claude Mythos 5.1 launched on 1 September, with access to the AI model only granted to approved partners.
The model, which has relaxed safeguards, is restricted to organizations involved in the company’s Project Glasswing, formed after the launch of the original Mythos model earlier this year.
According to the Financial Times, UK government officials have raised concerns that the decision to withhold access highlights a “wider protectionist shift” among US tech companies. (Ross Kelly / IT Pro)
Related: Financial Times, The Times
The United States is engaging in a broader range of espionage against China, including Chinese companies, to address the country’s status as both a military and an economic threat, the deputy CIA director, Michael Ellis, said.
During a rare public speaking appearance, Ellis said the nature of intelligence collection by the CIA and other intelligence agencies had evolved considerably since they were created during the Cold War to spy on the Soviet Union.
Unlike past geopolitical rivals, China “poses a fundamentally different kind of threat to us because the competition is economic,” Ellis said at a cybersecurity conference in Washington.
Western officials say that under Communist Party rule, China does not have an independent business community akin to the United States or much of Europe. Ellis said that makes Chinese companies a legitimate target for espionage in areas like artificial intelligence, semiconductors and biotechnology.
The CIA has needed to broaden its spying mandate because valuable intelligence about those technologies is “not found in the same places that political or military foreign intelligence is found,” Mr. Ellis said. Such information, he added, is “resident in the private sector — or in which China has to come as close as you might describe as a private sector.” (Dustin Volz / New York Times)
Related: CyberScoop, The Record, NextGov/FCW, Meritalk, C-SPAN
For its September Patch Tuesday fixes, Microsoft issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever.
Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
This month’s patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security vulnerabilities. September’s Patch Tuesday brings this year’s total to more than 2,600, more than twice Microsoft’s previous record-setting patch year in 2020 (1,245), and with three more months to go.
There are two “zero-day” flaws fixed this month that are being actively exploited: both CVE-2026-81963 and CVE-2026-85880 allow an attacker to elevate their privileges on a Windows system.
Fully 113 of the bugs addressed today earned Microsoft’s “critical” rating, meaning they could be abused by malware or miscreants to seize control over a vulnerable Windows machine with little or no help from the user.
Among the more serious critical flaws this month is CVE-2026-69730, a DNS weakness present in Windows Server 2012 onward and on Windows 10. Microsoft warns that an unauthenticated attacker could leverage this weakness simply by sending a specially crafted packet to an affected system, and that it is likely to be exploited.
Also scary is CVE-2026-69829, a critical remote code execution flaw in the Windows Shell. This vulnerability has a CVSS base score of 9.8 (10 is the most severe), and can be exploited with low attack complexity, no privileges, and no user interaction.
Tyler Reguly, associate director of security research and development at Fortra, said one core challenge with deploying Windows updates is that they need to be tested before being installed across an organization because not all third-party software works seamlessly in the face of changes to the underlying operating system.
“It’s time to put our CISOs and CSOs on notice,” Reguly said. “How are you helping your teams through these difficult times? Do you have your teams deploy after hours and on weekends to avoid disruption to the business environment? Do you reward them for that effort? Time to dig into your budget and buy dinner for your teams that are working on Saturday to get patches rolled out before users return to work on Monday.” (Brian Krebs / Krebs on Security)
Related: Zero Day Initiative, BleepingComputer, The Verge, Microsoft Security, CSO, The Cyber Express, CyberScoop, The Register, The Record, SANS Internet Storm Center, Ask Woody, The Cyber Express, Security Affairs, Ars Technica, Security Week, Thurrott, Windows Central, Neowin, Security Affairs

Google patched 230 vulnerabilities, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year.
"Google is aware that an exploit for CVE-2026-87491 exists in the wild," the company said in a Tuesday security advisory.
The company began rolling out patched versions to Windows (153.0.8010.36), Mac (153.0.8010.37), and Linux (153.0.8010.36) systems in the Stable Desktop channel two days after Jihyeon Jeong, a research intern at Seoul National University's Compsec Lab, reported it to Google.
Google says the security update could take days or weeks to reach all Chrome users worldwide, but it was available immediately when BleepingComputer checked for updates earlier today.
Those who prefer not to update manually can rely on Chrome to automatically check for updates and install them at the next launch. (Sergiu Gatlan / Bleeping Computer)
Related: Chrome, Help Net Security
US Border Patrol is running secretive predictive policing units that analyze Americans’ financial activity and other data, then feed that intelligence to local police who pull people over who are not suspected of any specific crime, but who the government thinks may be worth searching, 404 Media has found.
The units, the name of which 404 Media is revealing here for the first time, are called Predictive Intelligence Targeting Teams (PITT). In one case, a PITT analyzed the financial activity of a man who was driving across Montana, and local authorities stopped him under the pretense of an obstructed license plate and charged him with a DUI.
404 Media identified one PITT in the Spokane Sector, Washington, which polices the US border with Canada, and another in the Laredo Sector, Texas, which polices the border with Mexico. The findings add to an Associated Press investigation from last year which found Border Patrol was using automatic license plate readers (ALPRs) as part of the same wide-spanning predictive policing program.
“The bottom line is genuine probable cause cannot be synthetically generated,” Jake Laperruque, deputy director of the Security and Surveillance Project at the Center for Democracy & Technology, told 404 Media in an email. Here Border Patrol seems to be “using parallel construction to cloak the reason behind its car stops in secrecy. If we can't meaningfully review and evaluate these systems, we can't trust them,” he added. (Joseph Cox / 404 Media)
Related: The New Republic
In January, the New York police department’s counter-terrorism unit sent out a memo warning police officers about a new potential “security and counterintelligence” threat: Ray-Ban Meta glasses.
The memo directed officers to “conduct thorough inspections of all eyewear permitted within inmate cells” and cautioned that people who have been arrested could use these glasses, equipped with small cameras and microphones, to record inside police facilities. The memo cited two examples of such videos posted on social media.
“The ability to covertly record inside a law enforcement or detention facility, could result in a security risk if proprietary information about cell layouts, camera placements, or officer patrol/site protection routines are released,” the memo read.
The NYPD memo is one of a dozen, previously unreported and reviewed by the Guardian, that showed law enforcement agencies across the US are increasingly concerned about the potential for smart glasses to be used against them. Officers from Maine to California worry the technology will be used either to record officers and facilities secretly or to aid in the execution of crimes and acts of terrorism.
One of the videos, taken with smart glasses and posted to TikTok in July 2025, offered a rare peek into a South Carolina detention center that had been the subject of a federal investigation over unsafe conditions.
“Everyone here is trying to figure out what’s going on with my glasses, why my light is blinking,” the user said about other detainees in the video. (Johana Bhuiyan / The Guardian)
Related: UA.news, Decrypt, r/technology
An Ohio man, James Strahler II, was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims via phone calls, voicemails, text messages, and online posts.
He was also charged with anonymous telecommunications harassment and child pornography production and distribution.
According to court documents, Strahler used more than 100 AI web-based models and more than 24 AI platforms to generate sexually explicit videos and images of his victims.
"From December 2024 until June 2025, Strahler sent harassing messages to at least six adult female victims. These messages included nude images of the victims, both real and AI-generated," the Justice Department said.
"Strahler created more than 700 images of both real victims and animated persons and posted them to a website dedicated to child sexual abuse. An additional 2,400 images and videos on his phone were flagged as depicting nudity, morphed child sexual abuse material or violence."
He shared AI-generated pornographic videos with his victims' co-workers and demanded nude photos from the mothers of multiple women he was harassing, threatening to leak the forged obscene content of their daughters if they didn't comply.
Strahler also left his victims voicemails with rape threats that mentioned their home addresses and posted online child sexual abuse material he had generated using AI.
Strahler pleaded guilty in April to cyberstalking, producing obscene visual representations of child sexual abuse, and publication of digital forgeries charges, and was the first defendant to be convicted of violating the new Take It Down Act.
The Take It Down Act was enacted in 2025 to prohibit online publication of explicit content and AI forgeries without consent (also known as "revenge porn"). (Sergiu Gatlan / Bleeping Computer)
Related: Justice Department, WSYX, 10TV, WLWT, Cleveland.com
German cybersecurity startup Nebty discovered that a massive operation dubbed “DoppelCart” uses more than 119,000 domains to run a network of fake e-shops that steal payment card details.
Most of the domains are in the .SHOP top-level domain, accounting for 2.72% of all sites on the TLD.
Nebty describes it as the largest publicly documented fake-shop cluster by domain count, far surpassing the second-largest, “BogusBazaar,” which operated a network of 75,000 sites that recorded an estimated 850,000 fraudulent transactions.
The company's latest scans show that more than 105,000 DoppelCart shops are still active.
Nebty CEO Benedikt Scheungraber said that 96% of the shops confirmed to be part of DoppelCart share identical build files and resolve to 27 commerce backends.
Separately, Nebty created a searchable database to help companies identify DoppelCart impersonation and brand abuse and take appropriate action to protect themselves. (Bill Toulas / Bleeping Computer)
Related: Nebty, r/threatintel

The anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates.
ShieldCrash is described as a bypass for the ShieldBreak Defender privilege escalation flaw patched on Thursday, which itself bypassed RoguePlanet, another Defender flaw disclosed in June and patched by Microsoft in July.
According to Nightmare Eclipse, the ShieldCrash proof-of-concept exploit lets attackers gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems, but will not give them write access to the compromised systems.
"Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that ShieldBreak caused. While Microsoft fixed several things to prevent re-exploiting the issue, they missed a spot where ShieldBreak can still be exploited," they said.
"This PoC demonstrates an arbitrary file read as SYSTEM with September 2026, all supported windows versions are affected. I might rework this later into a full SYSTEM PoC but for now I'm dropping this skeleton PoC because I'm feeling a bit lazy."
Nightmare Eclipse released these zero-day exploits as part of an ongoing dispute with Microsoft over the company's bug bounty and vulnerability disclosure practices.
Microsoft responded with warnings of legal action against anyone engaging in "malicious activity causing real harm" to its customers, prompting many to believe that the company was directly threatening the security researcher. (Sergiu Gatlan / Bleeping Computer)
Related: GitHub, Security Affairs
German business software giant SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code.
Tracked as CVE-2026-44756 and dubbed OVERPASS by Onapsis security researchers who reported it, the vulnerability stems from a classic buffer overflow weakness in the Extended Passport Protocol (EPP) processing library.
Successful exploitation lets unprivileged threat actors run arbitrary commands on vulnerable SAP hosts with administrative privileges, leading to full compromise of the underlying SAP processes and business data.
The flaw can be exploited over SAP Internet Communication Manager (ICM), the networking component of the SAP Application Server that connects the SAP System (SAP NetWeaver Application Server) to the Internet via HTTP, HTTPS, and SMTP.
According to Onapsis' estimates, more than 10,000 Internet-facing SAP systems use the vulnerable component and are potentially exposed to attacks exploiting the CVE-2026-44756 flaw. (Sergiu Gatlan / Bleeping Computer)
Related: SAP, Infosecurity Magazine
Elon Musk, the world’s richest person, is funding an aggressive advertising campaign encouraging people in key states to check their registration status at a website, votesafe.org, to lure people away from the official US government website, vote.gov, and harvest their data.
Votesafe is run by America PAC, Musk’s super PAC.
Vote.gov, which is run by the Election Assistance Commission (EAC), does not ask for your personal information or track your activities. According to the site’s privacy policy, the EAC “does not collect personally-identifiable information about you when you visit our site, unless you choose to provide such information to us.”
But Musk's website was updated to allow America PAC to “share” or “sell” personal information with “our business partners.” This includes selling information about “whether you are registered to vote” and “how you submit your vote… where permitted by law.”
In addition to selling your personal information, America PAC can also sell “inferences” it makes from the information it collects, including “psychological trends, predispositions, behavior, attitudes, intelligence, abilities and aptitude.” The “business partners” can then disclose your information to other parties.
Users also agree to receive calls and texts, not only from America PAC, but also from “related entities as well as third parties.”
Over the last week alone, America PAC has spent over $180,000 promoting votesafe.org on Meta. Some of the ads are innocuous-looking messages, just reminding people to vote.
Other Meta ads attack “socialists” or specific Democratic Senate candidates with incendiary messages. America PAC also launched YouTube ads attacking Democratic candidates. Nearly all of these ads promote VoteSafe.org at the end.
Overall, Musk has pledged to spend over $100 million in the midterm elections, focusing on turnout. The data collected through votesafe.org looks to be central to this effort. (Judd Legum / Popular Information)
Related: The New Republic

Best Thing of the Day: It's Not Nice to Leak Crime Victims' Data
Korea's gender equality ministry said it is considering filing a complaint against Google for allegedly leaking the personal data of digital sex crime victims.
Worst Thing of the Day: Meta Says Trust Us Yet Again
Meta announced the release of Muse, a personal AI agent that people can message to automate digital tasks in a secure cloud environment, all while relying on security and privacy that the company says is “built into it” from the start.
Closing Thought
