China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies

2026-09-08T19:23:47Z1b79a17f596b30f69a2156babc5153d7ea39b9185a6da8983ce6897ce12a07fd
CVE-2025-66376AI model theftCISAChina-nexusGunraICSOTRaaSRussia-nexusSiemens S7 PLCZimbracloud securitycritical infrastructurecybersecurity advisoriesindustrial control systemsknowledge distillationnetworking devicesphishingransomwarered teamstate-sponsored activity

What happened

A CISA RSS collection of joint cybersecurity advisories published in July–September 2026. The advisories cover industrial-scale AI model distillation and proprietary capability theft attributed to China-based AI companies; red-team findings on domain, cloud, and OT compromise; active threats to Siemens S7 PLCs; Gunra ransomware; Russian exploitation of Zimbra Collaboration Suite using CVE-2025-66376; Russian state-sponsored targeting of vulnerable networking devices; and China-nexus covert networks of compromised infrastructure.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_alerts
Record identifier
1b79a17f596b30f69a2156babc5153d7ea39b9185a6da8983ce6897ce12a07fd
Enrichment time
2026-09-08T19:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.