Bottom line: According to research by Dream, largely autonomous AI agents carried out a four-day attack campaign against Asian government networks, while Taiwan reported an AI-driven cyberattack on government agencies during the same period.
Researchers at security company Dream have documented a four-day attack campaign in which AI agents based on open-source frameworks compromised government systems in Asia largely on their own. Taiwan’s Ministry of Digital Affairs confirmed an AI-supported attack on government agencies during the same period.
According to Dream, the campaign ran over four days in early July, with multiple AI agents working in parallel to map networks, identify vulnerabilities, and execute attack steps across connected systems. During this period, the “agentic attacker” produced 1,395 files, cracked 85 credentials, exfiltrated thousands of personnel records, and gained persistent access to state infrastructure, according to Dream. The company described the activity as a “near-autonomous attack” and called it a turning point for AI-driven offensive operations. Dream did not name the affected country, referring only to “government entities in Asia.” According to Reuters, Taiwan’s Ministry of Digital Affairs reported an “AI agent-assisted” cyberattack on government agencies during the same period, in which tools such as OpenClaw were used. Neither side has explicitly confirmed a direct connection between the Dream report and the Taiwanese incident. A Dream spokesperson told CSO that the company could not comment on the identity of the target or the attacker and had found no evidence of a confirmed compromise of the systems. Following publication of the original blog post, Dream said it had also found indications of the use of a model called DeepSeek-V4-Flash within the framework, but could not rule out that other models were involved.
For CISOs, this case marks a transition from AI as a mere support tool to AI systems that independently conduct multi-stage attack campaigns. According to the researchers, the attack framework was based on Hermes and OpenClaw agents that deployed multiple sub-agents simultaneously — each assigned to specific targets and tasks across successive waves of attack. Across a total of twelve attack waves, the agents carried out reconnaissance, credential attacks, and exploitation in parallel, supported by planning loops and feedback mechanisms. This enabled the system, according to Dream, to “carry out an attack campaign rather than merely answer questions about one.” Colin Ferris, Head of Threat Hunting and Incident Response at Silverfort, put this in context: the use of multiple agents working in parallel shows how such systems can divide tasks and adapt in real time. AI is doing for cybersecurity what cheap drones did for conventional warfare — attackers can deploy a handful of low-cost AI agents to continuously find and exploit gaps that have not yet been closed.
According to Dream, the campaign’s entry point was automated reconnaissance: the system mapped government infrastructure by extracting API endpoints and authentication configurations from publicly accessible code. In doing so, the framework identified unauthenticated APIs that exposed user data, in one case even a complete user database with no authentication whatsoever. For CISOs, this highlights two well-known but often neglected attack surfaces: exposed APIs and credentials stored in public code. Since Dream emphasizes that the cost of carrying out a competent attack has fallen while defense costs have remained just as high, security leaders should assess whether API inventories, credential rotation, and monitoring for authentication anomalies are keeping pace with a threat landscape increasingly shaped by autonomous, parallel-operating agent systems.
Source: www.csoonline.com · Published August 13, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.