As cited
Copy frozen at (site build).
threat intel
Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan
Researchers at Israeli cyber firm Dream identified a suspected Chinese cyberattack against Taiwan's government that used open-source AI models to conduct what they call a 'near-autonomous' operation. The attackers extracted over 2,500 personnel records and expanded the campaign to target government IT supply chain vendors, a nuclear safety agency, an email system, and energy sector companies, with the AI framework adapting mid-operation through autonomous vulnerability research and learning from failures. The attack demonstrates that while AI-powered offensives still require significant human tuning and fine-tuning to operate effectively, threat actors are increasingly embedding autonomous capabilities into their campaigns.
Why it matters: Government agencies, critical infrastructure operators, and government contractors in Taiwan and elsewhere need to assume adversaries are now combining AI frameworks with supply chain targeting; defenders should inventory exposed admin interfaces, patch misconfigurations, and monitor for coordinated scanning of parallel targets.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan
Suspected Chinese hackers deployed open-source artificial intelligence models to conduct a near-autonomous attack against Taiwanese government infrastructure, extracting over 2,500 personnel records and expanding operations to supply chain vendors, a nuclear safety agency, and energy sector companies. The attack framework used Hermes and OpenClaw AI models with autonomous learning cycles to search vulnerability databases and GitHub for exploitable techniques, adapting mid-operation without human intervention. Researchers at Dream identified the campaign through an archived dataset and noted that while the attack demonstrated significant sophistication in agent coordination and self-correction logic, it still required human fine-tuning and adjustment to function effectively.
Why it matters: Government security teams and critical infrastructure operators in Taiwan and beyond face emerging threats from AI-augmented attacks that can simultaneously scan multiple targets for vulnerabilities, requiring urgent evaluation of detection and response capabilities against adaptive adversaries.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan
Suspected Chinese hackers deployed open-source artificial intelligence models to conduct a near-autonomous attack against Taiwanese government infrastructure, extracting over 2,500 personnel records and expanding operations to supply chain vendors, a nuclear safety agency, and energy sector companies. The attack framework used Hermes and OpenClaw AI models with autonomous learning cycles to search vulnerability databases and GitHub for exploitable techniques, adapting mid-operation without human intervention. Researchers at Dream identified the campaign through an archived dataset and noted that while the attack demonstrated significant sophistication in agent coordination and self-correction logic, it still required human fine-tuning and adjustment to function effectively.
Why it matters: Government security teams and critical infrastructure operators in Taiwan and beyond face emerging threats from AI-augmented attacks that can simultaneously scan multiple targets for vulnerabilities, requiring urgent evaluation of detection and response capabilities against adaptive adversaries.
- Source published
- First seen by Cybersecurity Tracker