Disruption is a Fact of Life
Dennis G. Perry, PhD, MBA
August 21, 2026
Somebody left the workshop unlocked.
In early July, threat researchers at Dream Security, an Israeli cyberdefense firm, recovered the complete operational workspace of an attacker: 160 megabytes, 1,395 files, the whole thing [1]. Not fragments pieced together from logs. The actual working directory of an intrusion campaign, abandoned or exposed, sitting there to be read like a journal.
What the journal described was not a hacker. It was a system.
The framework was assembled from two publicly available open-source AI agent platforms, Hermes and OpenClaw [1]. It deployed up to eight sub-agents in parallel, each with a letter designation (researchers observed Agent A through Agent Q across the campaign), each assigned its own target and technique [1]. Over roughly four days, July 1 through July 4, it ran twelve attack waves against government systems in the Asia-Pacific region [1], [2]. Dream declined to name the victim. The Financial Times reported that a person familiar with the incident identified it as Taiwan, and the exfiltrated data was in Traditional Chinese, which narrows the map considerably [3].
The tally: 21 government systems mapped, 85 employee accounts cracked, more than 2,500 personnel records exfiltrated, and a persistent foothold inside state infrastructure [1], [4]. Before it was done, the operation had expanded its attention to Taiwan’s nuclear safety agency, government technology suppliers, and at least seven energy companies [5].
Human beings were involved. Dream calls it “near-autonomous,” and the operators’ internal notes were written in Simplified Chinese, which is why researchers say there is a high probability the operator was connected to mainland China, though they stopped short of formal attribution [2], [3]. But the humans were supervisors, not operators. The agents did the reconnaissance, found the vulnerabilities, ran the exploits, evaluated their own results, and adjusted [2].
Here is the part that should bother you more than the headline.
The vulnerabilities were boring. The system got in through a signature validation error in an authentication service and a set of unauthenticated API endpoints [6]. No zero-days. No exotic tradecraft. These are the kinds of flaws that sit on penetration test reports for years, and they sat there because, historically, nobody with the patience and skill to chain them together had gotten around to that particular target. Patience and skill were the scarce resources. The backlog of unexploited mediocrity was protected by attacker economics, not by anything the defenders did.
That protection just expired. A competent human red team costs six figures and works business hours. Eight agents work in parallel, around the clock, for the price of compute, and the twelfth wave is smarter than the first. The recovered archive documented what Dream calls Learning Cycles: between waves, the system searched vulnerability databases, code repositories, and published security research for techniques matched to the specific systems it was targeting, scored candidate attack chains by likelihood of success, and shifted effort toward the promising ones [7]. Separate agents rechecked findings before the system treated them as confirmed, filtering out its own false positives [7]. That is not a script. That is a methodology, executing itself.
Now, a caution before anyone (including me) reaches for the fainting couch. Dream sells AI-powered cyberdefense. Their report says the cost of attack has collapsed while the cost of defense has not, and that offensive AI is at an “inflection point” [4]. Both claims serve their business model, which does not make them false, but it does mean they arrive pre-marinated. My rule for vendor research is the same rule Paul gave the Thessalonians: test everything; hold fast what is good (1 Thessalonians 5:21). The artifacts here are good. A recovered operational workspace is about the strongest evidence a threat researcher ever gets, far stronger than the inference-from-telemetry that most attribution reports lean on. The adjectives are marketing. Keep the files, discount the framing.
And this was not a one-off. An AI-assisted automated campaign hit the Mexican government between December 2025 and February 2026 (it mostly failed) [2]. Anthropic reported last November that suspected Chinese state-linked actors had manipulated its Claude model to probe roughly thirty companies and agencies [3]. The Taiwan campaign is not the beginning of a trend. It is the first time the trend left its diary behind.
So what actually changes?
For twenty years, defensive strategy has quietly assumed a human on the other end: someone who gets tired, prioritizes, moves on when a target looks hard. Machine-speed reconnaissance breaks that assumption at its foundation. When enumeration is nearly free, everything discoverable gets discovered, fingerprinted, and scored. Which means discoverability itself is now the liability. An agent swarm is extraordinarily good at finding and ranking what it can see, and completely helpless against what it cannot enumerate. Architectures that make systems non-addressable, invisible to network scanning rather than merely hardened against it, get more valuable in exact proportion to how automated the attacker becomes. The energy companies on this operator’s target list should be sitting with that thought this week.
The uncomfortable question I have not resolved is what defense at machine speed actually requires of us. Dream’s researchers argue that defenders must adopt AI at the same scale and tempo as the attackers, and the logic is hard to refute: humans reviewing alerts cannot keep pace with agents generating them [2]. But an autonomous defensive system with the authority to act at machine speed inside your network is itself a powerful agent inside your network, with everything that implies. We watched what eight of them did to somebody else’s infrastructure over a long holiday weekend.
I do not have a clean answer for that one yet. Neither, as far as I can tell, does anyone else.
References
[1] Dream Security, “Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia,” Dream Security Blog, Aug. 12, 2026. [Online]. Available: https://www.dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia
[2] R. Lemos, “China-Linked Hacker Shows AI Capabilities in APAC Attack,” Dark Reading, Aug. 19, 2026. [Online]. Available: https://www.darkreading.com/cyberattacks-data-breaches/china-linked-hacker-ai-capabilities-apac-attack
[3] “Suspected China-linked hackers used AI to run the first-ever end-to-end autonomous cyberattack on Taiwan’s government, Israeli firm says,” Tom’s Hardware, Aug. 2026. [Online]. Available: https://www.tomshardware.com/tech-industry/cyber-security/suspected-china-linked-hackers-used-ai-to-run-the-first-ever-end-to-end-autonomous-cyberattack-on-taiwans-government-israeli-firm-says-open-source-built-tool-continuously-devised-effective-hack-strategies-in-real-time
[4] “AI agents wage near-autonomous cyberattack on Asian government networks,” CSO Online, Aug. 2026. [Online]. Available: https://www.csoonline.com/article/4209210/ai-agents-wage-near-autonomous-cyberattack-on-asian-government-networks.html
[5] “AI Agents Target Taiwan in a Near-Autonomous Cyberattack,” Kingy AI, Aug. 2026. [Online]. Available: https://kingy.ai/news/ai-agents-attack-taiwan-cyberattack/
[6] “China-Linked Autonomous Cyberattack on Taiwan Explained,” Cyber Magazine, Aug. 2026. [Online]. Available: https://cybermagazine.com/news/china-linked-autonomous-cyberattack-on-taiwan-explained
[7] “Autonomous AI agents hit Asian government in four-day breach,” IT Brief Asia, Aug. 2026. [Online]. Available: https://itbrief.asia/story/autonomous-ai-agents-hit-asian-government-in-four-day-breach
Leave a Reply