LIVE FEED
Chinese AI Firms Accused of Distilling OpenAI and Anthropic Models

Chinese AI Firms Accused of Distilling OpenAI and Anthropic Models

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 8.5 Dark Reading

US government agencies allege that Chinese AI companies covertly extracted billions of tokens from leading frontier models — including OpenAI, Anthropic, Google Gemini, and Grok — to build competing systems at reduced cost. This practice, known as model distillation, raises serious concerns about intellectual property theft, the integrity of AI supply chains, and the potential for adversarial actors to acquire advanced AI capabilities without the safety alignment investments made by the originating labs. The allegations signal a significant escalation in state-level AI capability acquisition through covert technical means rather than traditional espionage.

CVE-2026-44827: Hugging Face Diffusers RCE Bypasses Trust Gate

CVE-2026-44827: Hugging Face Diffusers RCE Bypasses Trust Gate

ATLAS OWASP CRITICAL Active exploitation · Immediate action required ▲ 9.1 The Hacker News

Three high-severity vulnerabilities in Hugging Face's Diffusers library — collectively dubbed FaceHugger — allow crafted model repositories to execute arbitrary code even when the trust_remote_code safeguard is explicitly disabled. The flaws exploit a TOCTOU race condition in the library's two-phase model loading process, meaning the security gate only inspects the first HTTP request while a malicious payload can be injected via the second. With over 8.1 million downloads in July 2026 alone, the attack surface spans enterprise production pipelines, CI/CD systems, and container images globally.

Anthropic's Mythos 5 and Fable 5 Hit by Export Block

Anthropic's Mythos 5 and Fable 5 Hit by Export Block

FIRST LOOK ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.2 TechCrunch AI

The Trump administration's June 2026 export block on Anthropic's Mythos 5 and Fable 5 models has forced a long-overdue reckoning with AI vendor dependency as a first-class operational risk, giving security and procurement teams the concrete, real-world evidence needed to justify resilience investments that were previously treated as theoretical. This event closes a critical gap in organisational risk registers by demonstrating that AI model access continuity must be governed with the same rigour applied to any mission-critical third-party dependency — complete with contingency planning, contractual protections, and evaluated alternatives. What remains unaddressed is the absence of industry-wide standards for AI vendor continuity obligations, leaving individual organisations to negotiate protections without consistent benchmarks.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.