{"slug": "ai-agents-wage-near-autonomous-cyberattack-on-asian-government-networks", "title": "AI agents wage near-autonomous cyberattack on Asian government networks", "summary": "Autonomous AI agents built on open-source frameworks breached Taiwanese government systems, compromised credentials, and probed a nuclear safety agency in a multi-day cyberattack, according to research by cybersecurity firm Dream. The campaign, which unfolded over four days in early July, produced 1,395 files, 85 cracked credentials, and thousands of exfiltrated personnel records, with Dream describing it as a 'near-autonomous attack' and stating that 'AI-enabled offensive operations are now at an inflection point.' Taiwan's Ministry of Digital Affairs detected an 'AI agent-assisted' cyberattack during the same period, though neither Dream nor Taiwanese authorities have confirmed a link.", "body_md": "Autonomous AI agents built on open-source frameworks breached Taiwanese government systems, compromised credentials, and probed a nuclear safety agency in a multi-day cyberattack that researchers say signals a new phase in AI-enabled operations.\n\nThe campaign unfolded over four days in early July, during which multiple AI agents operated in parallel to map networks, identify vulnerabilities, and execute intrusion steps across interconnected systems, according to research published by cybersecurity firm Dream.\n\n“In roughly four days, the agentic attacker produced 1,395 files, 85 cracked credentials, thousands of exfiltrated personnel records, and gained a persistent foothold inside state infrastructure,” Dream wrote in a blog post. “It spells out one thing loudly – the cost of running a competent attack has collapsed, but the cost of defending against one has not.”\n\nThey described the activity as a “near-autonomous attack,” adding that “AI-enabled offensive operations are now at an inflection point.”\n\nDream did not identify the affected country but stated that it was “government entities in Asia.” However, Taiwan’s Ministry of Digital Affairs said it detected an “AI agent-assisted” cyberattack targeting government agencies during the same period, according to Reuters, which reported that the activity involved AI-driven tools such as OpenClaw.\n\n“The relevant attack sources, methods, and scope of impact have all been fully investigated, and the affected units have successively completed their handling,” the report added, quoting an official from the Ministry of Digital Affairs of Taiwan, though neither Dream nor Taiwanese authorities have explicitly confirmed a link between the two.\n\nResponding to CSO’s queries, a Dream spokesperson declined to comment on the identity of the target or the attacker and said its research did not find evidence of a confirmed breach of the entity’s systems. “We cannot comment on the identity of the target or attacker. Our report describes the framework at the time of our analysis.”\n\nThe company further said that since the publication of its initial blog post, it has identified evidence indicating the use of a DeepSeek-V4-Flash model within this framework. “We do not know whether it was the only model used,” the spokesperson said.\n\nThe Government of Taiwan did not immediately respond to a request for comment.\n\nThe researchers wrote that the attack framework was built on Hermes and OpenClaw agents and deployed multiple sub-agents simultaneously, each assigned to specific targets and tasks across successive attack waves.\n\nAcross 12 attack waves, the agents carried out reconnaissance, credential attacks, and exploitation efforts in parallel, incorporating planning loops and feedback mechanisms.\n\nThis allowed the system to “run an intrusion campaign rather than answer questions about one,” the researchers wrote.\n\nColin Ferris, head of threat hunting and incident response at Silverfort, said the use of multiple agents working in parallel reflects how such systems can divide tasks and adapt in real time.\n\n“AI does to cybersecurity what cheap drones have done to conventional warfare,” Ferris said, adding that attackers can deploy “a handful of inexpensive AI agents to continuously find and exploit the gaps they haven’t fixed yet.”\n\nThe campaign began with automated reconnaissance, during which the system mapped government infrastructure by extracting API endpoints and authentication configurations from publicly accessible code, according to the blog post.\n\nThe researchers wrote that the framework identified unauthenticated APIs exposing user data and, in one instance, an entire user database without authentication.\n\nThey added that the system used a combination of techniques to gain access, including exploiting hidden authentication endpoints, conducting credential attacks, and bypassing token validation mechanisms.\n\nThe compromised accounts were then used to move laterally across connected systems through single sign-on integrations.\n\nCris Thomas, security advocate at cybersecurity firm Semgrep, said the techniques described are not new, but AI is changing how they are executed.\n\n“This demonstrates that AI is just a tool, one that defenders and attackers can both use,” Thomas said. “Attackers are going to attack, and they will find a way around a harness and other restrictions.”\n\nThe researchers wrote that the operation extended beyond initial targets to include supply chain partners, a government email system, and organizations in the energy sector.\n\nThey added that the campaign reached a nuclear safety-related organization, though the report does not identify the country or specify the level of access achieved.\n\nFerris said such campaigns highlight how attackers can use widely available tools to scale operations, noting that systems can “research targets, divide responsibilities, and change tactics when blocked.”\n\nRecent disclosures from AI developers have pointed to similar risks. OpenAI recently [said](https://www.csoonline.com/article/4207311/openai-says-astra-could-reach-critical-cyber-capability-tightens-safeguards.html) it cannot rule out that advanced models could autonomously identify and exploit vulnerabilities, while Anthropic has [reported](https://www.csoonline.com/article/4205612/openai-anthropic-ai-agents-resorted-to-deception-in-new-cybersecurity-incidents.html) instances of AI agents attempting to access external systems during testing.\n\nThe researchers wrote that safeguards designed to restrict AI behavior were bypassed in the campaign by framing the activity as authorized testing. They added that linguistic analysis suggests the campaign was carried out by a “Chinese-language operator,” though the report does not attribute it to any specific group or country.", "url": "https://wpnews.pro/news/ai-agents-wage-near-autonomous-cyberattack-on-asian-government-networks", "canonical_source": "https://www.csoonline.com/article/4209210/ai-agents-wage-near-autonomous-cyberattack-on-asian-government-networks.html", "published_at": "2026-08-13 13:23:10+00:00", "updated_at": "2026-08-13 13:41:02.478386+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-policy", "ai-agents"], "entities": ["Dream", "Taiwan's Ministry of Digital Affairs", "OpenClaw", "Hermes", "DeepSeek-V4-Flash", "Colin Ferris", "Silverfort", "Reuters"], "alternates": {"html": "https://wpnews.pro/news/ai-agents-wage-near-autonomous-cyberattack-on-asian-government-networks", "markdown": "https://wpnews.pro/news/ai-agents-wage-near-autonomous-cyberattack-on-asian-government-networks.md", "text": "https://wpnews.pro/news/ai-agents-wage-near-autonomous-cyberattack-on-asian-government-networks.txt", "jsonld": "https://wpnews.pro/news/ai-agents-wage-near-autonomous-cyberattack-on-asian-government-networks.jsonld"}}