- Israeli cybersecurity firm Dream documented what it calls the first near-autonomous, end-to-end AI-agent intrusion against a government, targeting Taiwan.
- The operation ran on open-source frameworks, mapped roughly 21 systems, and stole more than 2,500 personnel records without a frontier-lab API.
- The agents expanded targeting on their own from core government sites to a nuclear safety agency, a government email system, and seven-plus energy companies.
Dream traces a near-autonomous intrusion built entirely on open-source agents
A cyber operation against Taiwan's government ran largely without human operators at the keyboard, according to an August 12 report from the Israeli cybersecurity firm Dream. The attackers, which Dream assesses to be linked to China, wired together open-source AI frameworks named Hermes and OpenClaw into a system that handled reconnaissance, vulnerability discovery, and intrusion as one continuous loop.
The framework ran what Dream describes as Learning Cycles, querying public vulnerability databases, GitHub repositories, and security research to find and adapt exploits in real time. It mapped around 21 systems, then widened its own scope beyond the initial government targets. Dream's researchers recorded the expansion in the report.
The attacker didn't stop at primary targets. It expanded the operation to government IT supply chain vendors, a nuclear safety agency, a government email system, and 7+ energy sector companies.Dream threat research report, August 12, 2026
By the end of the campaign the system had extracted more than 2,500 personnel records. It bypassed the safety guardrails on the underlying models by framing its own activity as authorized penetration testing, a social-engineering trick aimed at the AI rather than at a human.
| Systems mapped across government and infrastructure targets | ~21 |
| Personnel records extracted | 2,500+ |
| Energy sector companies pulled into the operation | 7+ |
| Open-source frameworks at the core (Hermes, OpenClaw) | 2 |
| Frontier-lab APIs required to run it | 0 |
Why open-source tooling changes the offensive math
The word Dream uses is near-autonomous, not autonomous, and the distinction matters. The campaign still needed significant human fine-tuning and oversight to function, so this is not yet a machine that plans and executes a state-grade operation on its own. What it shows instead is that the labor-intensive middle of an intrusion, the part that used to require a trained team scanning, testing, and pivoting for weeks, can now be handed to an agent loop that works at machine speed and expands targets in parallel.
The open-source detail is the sharp edge. Because the operators built on Hermes and OpenClaw rather than a commercial model API, they sidestepped the provider-side controls that frontier labs have spent years installing, the monitoring, rate limits, and abuse detection that sit between an attacker and a hosted model. There was no vendor in the loop to notice the pattern or pull access.
The barrier to a government-scale cyber operation used to be a team of skilled humans working for weeks. Dream's report shows that barrier is shrinking to a set of open-source agents, a modest amount of tuning, and a prompt that tells the model the break-in is a penetration test.
Santage is committed to independent, transparent journalism. This article is produced in accordance with Santage's Editorial Standards and aims to provide accurate and timely information. Readers are encouraged to verify information independently.