Security2 distinct publishers3 min readUpdated
Dream Security recovered a 160-megabyte workspace from a framework built on open-source agents. Taiwan's Ministry of Digital Affairs has confirmed AI-assisted attacks on government systems in July.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Israeli AI company Dream says its threat research team recovered the complete operational workspace of an autonomous attack framework that had been running intrusion campaigns against government entities in Asia, a 160-megabyte archive of 1,395 files found in early July 2026 [1][2]. Taiwan's Ministry of Digital Affairs confirmed on August 13 that foreign hackers used AI tools against government systems in July, saying its cybersecurity units detected the intrusion and responded under established procedures [3][4].
The operating tempo is the story. Dream documents 12 attack waves across roughly four days, July 1 to 4, with up to eight lettered sub-agents dispatched in parallel per wave and agents A through Q observed over the campaign [5][6]. That is about three waves per day [7] and roughly 349 files of output per day [8]. Dream reports 85 cracked government employee credentials, thousands of exfiltrated personnel records, a signature validation flaw discovered in the government's personal authentication service, and persistent backdoors installed on government web applications [9][10].
Reconnaissance started from one page. According to Dream, the framework downloaded and decompiled JavaScript bundles from an Angular-based government portal, pulled out embedded URLs, API endpoints, OAuth client IDs and Keycloak configuration, then identified 21 connected government systems and mapped the national SSO architecture including six sub-realms, all OIDC endpoints and two RSA signing keys [11][12].
The scaffolding matters more than the model. Dream describes posterior probability scoring used to continuously reprioritise 14 parallel attack chains, "Learning Cycles" that search vulnerability databases, GitHub and security publications when a technique is blocked, and structured after-action reports that feed each wave's results into the next without human intervention [13][14][15]. The framework was built on the Hermes and OpenClaw agents [16], which Taiwan News describes as open-source agent systems; humans picked the target and set the mission, and the AI handled much of the reconnaissance, testing and coordination [17]. Model refusals, the only real constraint in the stack, were bypassed by framing everything as authorised penetration testing [18].
Attribution is thin and stated as such. Dream's linguistic analysis notes code-switching between Simplified Chinese in internal status reports and Traditional Chinese in target-facing analysis, which it reads as a Chinese-language operator [19]. The Financial Times, which broke the story, called it possibly the first known end-to-end autonomous cyberattack against a government target and referred to "suspected Chinese hackers" [20]. The ministry attributed the activity to "overseas sources" and did not name China [21]. Dream withheld the identity of both the targets and the operator, and notified affected organisations before publishing [22].
The record count does not reconcile cleanly: Dream's own summary says thousands of personnel records, while Taiwan News reports Dream's figure as more than 2,500, along with follow-on targeting of the country's nuclear safety agency and at least seven energy companies [10][23]. Treat the exact number as unsettled.
Dream's conclusion is the one defenders should argue with or budget for: the cost of running a competent attack has collapsed and the cost of defending against one has not [24]. The ministry made a related point, telling the FT that AI agents bring dual challenges because attacks are automated and the agents themselves become new vulnerabilities [25]. For scale, Taiwan's National Security Bureau said in January that critical infrastructure faced an average of 2.63 million Chinese cyberattack attempts a day in 2025, 6 percent above the prior year [26].
Watch whether other national CERTs find the same harnesses in their own logs, and whether any vendor publishes detection guidance keyed to agentic behaviour rather than payloads.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Agents autonomously cracked government employee credentials, exfiltrated hundreds of personnel records from unauthenticated API endpoints, discovered a signature validation flaw in the government's personal authentication service, and installed persistent backdoors on government web applications.
In roughly four days the agentic attacker produced 1,395 files, 85 cracked credentials, thousands of exfiltrated personnel records, and gained a persistent foothold inside state infrastructure.
In early July 2026, DREAM Lab's Threat Research team uncovered the complete operational workspace of an autonomous AI attack framework that had been actively conducting intrusion campaigns against government entities in Asia.
The archive spanned over 160 megabytes and 1,395 files, revealing a multi-agent AI system that achieved confirmed real-world compromises against state infrastructure.
Dream documented 12 attack waves conducted over approximately four days, July 1 to 4, 2026.
The framework deploys up to 8 lettered sub-agents in parallel per wave, with Agent A through Agent Q observed across the campaign.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary artefact report plus government confirmation, targets withheld
The core incident is unusually well evidenced for an AI-attack story: a first-party technical report built on a recovered 160MB workspace, corroborated on the load-bearing numbers (1,395 files, up to eight parallel agents, four days, 21 systems, 85 accounts, Hermes/OpenClaw) by separate reporting and by a government confirmation. Evidence weakens on the parts only Dream can see: framework internals, guardrail bypass and the follow-on nuclear/energy targeting are single-sourced, target identities are withheld so nothing is externally checkable, attribution is contested, and Dream's own record counts are inconsistent between passages.
One government-confirmed campaign using off-the-shelf agents
This is real-world use, not a lab demonstration: a four-day campaign with confirmed compromises against state infrastructure, publicly acknowledged by the affected government, built on readily available open-source agent harnesses. Adoption is not higher because the supplied sources document a single operator and a single campaign window; there is no evidence of multiple operators, repeat campaigns or other victims beyond the reported follow-on targeting, which itself is single-sourced.
Autonomy framing runs ahead of the documented human role
Framing overstates autonomy modestly. 'First known end-to-end autonomous cyberattack' is hedged as 'may be' by the outlet relaying the FT, Dream itself says 'what appears to be a near-autonomous attack', and both sources agree human operators chose the target and set the mission. The report also concedes its AI static-analysis findings produced zero confirmed exploits, with the actual breaches coming from server-side flaws. Against that, the underlying incident is government-confirmed and the artefact counts are corroborated, so the gap is a framing premium rather than a fabricated event.
Vendor-originated disclosure plus a government managing attribution
Both narrators have visible stakes. Dream Security is a commercial AI security company publishing an inflection-point thesis about the threat class it sells against, it pre-briefed the Financial Times to seed coverage, and its responsible-disclosure posture conveniently makes the central claims unverifiable by third parties. Taiwan's Ministry of Digital Affairs has its own incentives: it emphasises that its units detected, investigated and responded per procedure, and attributes to 'overseas sources' while declining to name China even as the FT reports 'suspected Chinese hackers'.
Event solid, mechanism and attribution softer
Confidence is high that an AI-assisted intrusion campaign against Taiwanese government systems occurred in early July 2026 and that it used open-source agent harnesses: two publishers agree and the affected ministry confirmed it. Confidence is materially lower on how autonomous the framework really was, on the exact exfiltration totals, on the follow-on nuclear and energy targeting, and on operator attribution — each of which rests on a single source or is explicitly contested.
build
A 160MB Attacker Workspace Is the First Real Parts List for Autonomous Intrusion1 distinct publisher
invest
China's crude imports fell to a 2016 low, and the self-sufficiency bill looks cheaper1 distinct publisher
build
A twelve-word joke became a discipline, and one seven-step chain had no loop to remove1 distinct publisher
invest
Jane Street's $990M in Bitcoin ETFs looks like inventory, not conviction1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026
1 article · August 18, 2026