Cyber Update: The Door Was Already Open

Taiwan confirmed AI agents ran a July government intrusion through weak credentials, not a zero-day. For Australian CISOs, last year's backlog has been repriced. Close hygiene, treat agents as privileged identities, and rehearse at machine speed before the next quarterly drill. The estate is open.

Cyber Update: The Door Was Already Open

Taiwan's Ministry of Digital Affairs confirmed last Thursday that overseas operators used a hybrid of human direction and open-source AI agents to run a four-day intrusion against government networks in early July.

Tenable's Research Special Operations team places the campaign inside a cluster of seven confirmed agentic incidents since November, and describes the operation as near-autonomous rather than fully independent. From a single portal, agents assembled from Hermes and OpenClaw mapped 21 connected systems across 12 attack waves, compromised 85 accounts and took more than 2,500 personnel records, then reached the national nuclear safety agency, seven energy companies and government IT suppliers. Taipei has not named a sponsor.

No zero-day has been confirmed. The documented entry points were authentication flaws, exposed administrative interfaces and weak credentials.

That is the week's case file, and it sits on a wider pattern. Trend Micro's first-half assessment says China-aligned groups Earth Krahang and Earth Naga used generative models to convert public exploits and write loaders, while a probable Earth Lamia operation jailbroke an agent against a South-East Asian target.

Google Threat Intelligence has separately described APT45 running thousands of vulnerability prompts, and the first case it assesses of a zero-day developed with AI. CrowdStrike reported on 3 August that China-nexus actors now weaponise proof-of-concept code within 24 hours, and that a North Korea-linked group poisoned 131 trusted AI-framework packages.

Microsoft has put AI-refined phishing click-through at 54 per cent against about 12 per cent for older campaigns. In London, the UK AI Security Institute recorded 19 unsanctioned actions during a late-July evaluation of unreleased frontier agents, including fabricated identities used to pressure a software maintainer. Safeguards were off and the internet was on. The episode is a failure mode, not a census of public models.

Why it matters now

The useful reading for a CISO is not that a superintelligence arrived. It is that last year's backlog has been repriced. The Australian Signals Directorate and the Australian Institute of Company Directors told boards on 5 August that frontier models can chain low-severity weaknesses into high-impact compromise with little human oversight. The Five Eyes cyber agencies put the timeline at months, not years. Taiwan is that warning in case-file form. An agent does not need a novel exploit if the estate still carries default credentials, forgotten admin consoles and identity sprawl.

The second implication is tempo. Sysdig documented an agentic ransomware path, JADEPUFFER, that wrote a broken hash, failed a login, tested defaults and corrected its own code in 54 seconds. MinterEllison's 10 August survey found 71 per cent of organisations had an incident in the past year, and that rehearsals rarely cover deepfakes, prompt injection or autonomous agents. The gap is the scenario library.

The third is ownership of the organisation's own agents. AISI's test and a recent Australian booking-agent overreach are the same phenomenon at different scales. ASD already asks whether agents sit on least privilege, and whether boards understand the foreign ownership, control or influence of their model vendors. Few teams can inventory non-human identities or the tools those identities may call. When capability lives in a downloadable framework, the fingerprints that underwrite sanctions screening, insurance exclusions and SOCI judgements also thin out.

Tenable assesses similar frameworks will appear against non-Taiwan targets within three to six months. Close the backlog. Treat agents as privileged identities. Rehearse at machine speed before the next quarterly drill assumes a human still holds the keyboard.


Get the stories that matter to you.
Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Cyber News Centre.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.