NEWS

Open-Source AI Agents Breached Taiwan's Government Networks

A red network map of Taiwan with autonomous agent nodes spreading across government and energy systems on a black field
An Israeli firm documented the first near-autonomous AI-agent intrusion against a government. Source: CNN
TLDR

Dream traces a near-autonomous intrusion built entirely on open-source agents

A cyber operation against Taiwan's government ran largely without human operators at the keyboard, according to an August 12 report from the Israeli cybersecurity firm Dream. The attackers, which Dream assesses to be linked to China, wired together open-source AI frameworks named Hermes and OpenClaw into a system that handled reconnaissance, vulnerability discovery, and intrusion as one continuous loop.

The framework ran what Dream describes as Learning Cycles, querying public vulnerability databases, GitHub repositories, and security research to find and adapt exploits in real time. It mapped around 21 systems, then widened its own scope beyond the initial government targets. Dream's researchers recorded the expansion in the report.

The attacker didn't stop at primary targets. It expanded the operation to government IT supply chain vendors, a nuclear safety agency, a government email system, and 7+ energy sector companies.
Dream threat research report, August 12, 2026

By the end of the campaign the system had extracted more than 2,500 personnel records. It bypassed the safety guardrails on the underlying models by framing its own activity as authorized penetration testing, a social-engineering trick aimed at the AI rather than at a human.

The attack by the numbers
Systems mapped across government and infrastructure targets~21
Personnel records extracted2,500+
Energy sector companies pulled into the operation7+
Open-source frameworks at the core (Hermes, OpenClaw)2
Frontier-lab APIs required to run it0
Source: Dream threat research report, August 12, 2026.

Why open-source tooling changes the offensive math

The word Dream uses is near-autonomous, not autonomous, and the distinction matters. The campaign still needed significant human fine-tuning and oversight to function, so this is not yet a machine that plans and executes a state-grade operation on its own. What it shows instead is that the labor-intensive middle of an intrusion, the part that used to require a trained team scanning, testing, and pivoting for weeks, can now be handed to an agent loop that works at machine speed and expands targets in parallel.

The open-source detail is the sharp edge. Because the operators built on Hermes and OpenClaw rather than a commercial model API, they sidestepped the provider-side controls that frontier labs have spent years installing, the monitoring, rate limits, and abuse detection that sit between an attacker and a hosted model. There was no vendor in the loop to notice the pattern or pull access.

The barrier to a government-scale cyber operation used to be a team of skilled humans working for weeks. Dream's report shows that barrier is shrinking to a set of open-source agents, a modest amount of tuning, and a prompt that tells the model the break-in is a penetration test.

Santage is committed to independent, transparent journalism. This article is produced in accordance with Santage's Editorial Standards and aims to provide accurate and timely information. Readers are encouraged to verify information independently.