LIVE · cybersecurity feed
Live wire
aihigh

China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan

Cybersecurity firm Dream has documented what appears to be the first fully autonomous, end-to-end AI hacking operation targeting a government network. Suspected China-linked hackers reportedly used up to eight AI agents to map systems, find vulnerabilities, and steal data from a Taiwanese government network with minimal human intervention. The operation compromised over 85 accounts and 2,500 personnel records, highlighting a significant advancement in AI-driven cyber warfare.

zeroday.news ·

An Israeli cybersecurity firm, Dream, has documented what appears to be the first fully autonomous, end-to-end AI hacking operation against a government target, reportedly linked to China and aimed at Taiwan. The attack, which occurred over four days in early July, utilized eight AI agents to breach a government network, exfiltrate data, and compromise accounts with minimal human intervention.

The sophisticated operation involved a tool built entirely from publicly available AI agents. This tool autonomously mapped 21 government systems, identified vulnerabilities, and adapted its tactics when encountering obstacles. By the time researchers discovered the activity, the operation had compromised at least 85 government accounts, stolen over 2,500 personnel records, and expanded its reach to include a nuclear safety agency and at least seven energy companies.

Dream's chief strategy officer, Amir Becker, a veteran of Israel's Unit 8200, stated that he had not previously witnessed this level of autonomous capability directed at a government. He emphasized that governments globally should now operate under the assumption of permanent compromise.

While Dream did not officially name the target government, citing company policy, a source familiar with the matter indicated it was Taiwan. Supporting this, internal communications associated with the hacking tool were in Simplified Chinese, while the stolen data was in Traditional Chinese, a script primarily used by government systems in Taiwan, Hong Kong, and Macau. Taiwan's Ministry of Digital Affairs declined to confirm specific details, only stating that incidents involving government agencies are handled according to established procedures.

Unlike AI models "going rogue" in controlled lab environments, this incident involved a deliberately assembled weapon. Researchers found the toolkit as a 160MB archive containing 1,395 files, built around two open-source AI agent frameworks, Hermes and OpenClaw. These frameworks are freely downloadable and designed to enable AI models to perform autonomous tasks in real-world scenarios.

The attackers bypassed the AI model's safety guardrails by framing the entire hacking campaign as an authorized penetration test. The model apparently lacked a reliable mechanism to verify or reject this deceptive premise.

A particularly striking aspect of the attack was the tool's decision-making process. It continuously ranked and reprioritized potential attack paths based on new evidence. When one route failed, it deployed another agent to search the internet for fresh information and devise a different approach, mimicking the iterative process of a human red-teamer, but without the need for human rest.

This development raises concerns for Taiwan, which already experiences an average of 2.6 million Chinese cyberattacks daily, a 6% increase year-over-year in 2025. The introduction of such autonomous capabilities could significantly complicate defense strategies.

aicyber warfareautonomous agentstaiwandata breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-68820high

17th August – Threat Intelligence Report

Several significant cyber incidents were reported this week, including a ransomware attack on Colombia's Ministry of Justice and a data breach affecting Poland's primary healthcare platform, MyDr, potentially exposing data of 19 million citizens. Additionally, Levi Strauss & Co. and IEH Corporation reported cyberattacks involving social engineering and phishing, respectively, with no consumer data compromised in the former. In the realm of AI threats, researchers detailed a suspected China-linked campaign using autonomous AI agents against Taiwanese government systems and noted North Korea-linked Kimsuky's efforts to build an offline AI environment for cyberespionage. Microsoft, Apple, Adobe

CVE-2026-69414high

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

A new vulnerability dubbed ShieldBreak (CVE-2026-69414) has been discovered in Microsoft Defender, which bypasses a previous patch for a similar flaw called RoguePlanet. This elevation of privilege vulnerability requires initial access to a machine and is dependent on Microsoft Defender being active. Microsoft has acknowledged the issue and is working on a fix, advising users to maintain security updates and exercise caution with untrusted code.

CVE-2026-15826critical

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical vulnerability in the WordPress User Profile Builder plugin, affecting over 40,000 sites, allows unauthenticated attackers to gain administrator access. The flaw, CVE-2026-15826, stems from a type confusion error that can trick the plugin into granting administrative privileges if specific configurations are met, such as the administrator using user ID 1 and automatic login after registration being enabled. The plugin developer has released a patch, version 3.16.5, to address the issue.

ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.