CISO Daily Digest: China-Linked AI Agents Autonomously Attacked Taiwan Government, Stole 2,500+ Personnel Records (20260813)
Dream Security reveals a China-linked Hermes + OpenClaw AI attack framework that ran 12 autonomous waves against Taiwan government systems in July — cracking 85 accounts and exfiltrating 2,564 personnel records before expanding to the nuclear safety commission and 7 energy firms, as moda confirms overseas origin. Also: SharePoint CVE-2026-55040 exploited within a day of PoC release, WordPress XSS2Shell CVE-2026-64638 (CVSS 8.9), Apple Screen Sharing CVE-2026-65400 root RCE, and the Jewelbug APT.
China-Linked AI Agents Autonomously Attacked Taiwan Government
On August 12, the Financial Times reported that suspected Chinese hackers used AI agents to autonomously attack Taiwan government agencies. The disclosure came from Israeli AI security startup Dream Security (founded by NSO Group co-founder Shalev Hulio, former Austrian Chancellor Sebastian Kurz, and Wayout Group founder Gil Dolev). Taiwan’s Ministry of Digital Affairs (moda) confirmed the next day: its monitoring units detected abnormal attacks against government agencies as early as July, the investigation is complete, and affected units have been remediated. moda stated the attacks originated overseas and followed a human-operated plus AI-assisted execution model — agents built on OpenClaw and other frameworks chain attack techniques quickly and cheaply, pivoting through backup and test platforms; the National Institute of Cyber Security had already issued a warning on July 20.
What happened:
- Dream Security identified an attack framework built on Hermes and OpenClaw that can run up to 8 AI agents concurrently — dividing up target discovery, vulnerability mining, and strategy adjustment when attacks hit obstacles.
- Between July 1–4, the framework ran 12 waves of attacks: it probed 21 government systems, cracked 85 government employee accounts via password spraying, gained access to 84 internal systems (dashboards, device management, personnel statistics), and exfiltrated 2,564 personnel records (1,409 employees, 916 users via an unauthenticated API, 239 legal professionals) — plus the full user database, 7 SSO client secrets, 6 database credentials, and internal IP ranges.
- Recon began with an Angular-based government portal: the framework decompiled JavaScript bundles, extracted embedded URLs, API endpoints, OAuth client IDs, and Keycloak configuration, then mapped the national single sign-on (SSO) architecture — 6 subdomains, all OIDC endpoints, 2 RSA signing keys. One system alone exposed 36+ API endpoints, many unauthenticated, including one that returned the entire user database.
- The campaign later expanded to the nuclear safety commission and at least 7 energy companies, scanning targets for misconfigurations and exposed management interfaces.
- The framework used a two-layer probabilistic decision mechanism with Bayesian posterior ranking to dynamically prioritize 14 parallel attack chains — the first documented case of an autonomous attack with self-directed prioritization. It also self-corrected, logging and discarding 7 false positives (e.g., a 21-second server delay initially flagged as SQL injection turned out to be an SMTP timeout), and cross-validated candidate vulnerabilities across multiple agents.
- Attacks were disguised as authorized penetration testing to bypass AI model safety mechanisms; when an approach failed, agents went online to research new methods.
Why This Reshapes AI Agent Governance
This is the first documented case of an AI attack framework running multiple autonomous agents simultaneously, with self-directed path prioritization and error correction — moving AI-enabled attacks from “assisted hacking” to “autonomous operations.” The target profile matters as much as the technique: national identity infrastructure (SSO, OIDC endpoints, unauthenticated APIs) is the crown jewel, and the chain shows how one exposed portal can be mapped into a full identity graph. The human+AI hybrid execution model also means defenders must assume attackers iterate faster than traditional signature-based detection, and that “authorized-looking” scanning activity can be AI-generated. For organizations operating critical infrastructure or government-adjacent networks, identity exposure — unauthenticated APIs, debug endpoints, credential spraying — is now an active AI-agent attack surface, not a theoretical one.
Active Threats This Week
📌 SharePoint CVE-2026-55040 exploited within a day of public PoC (update) — Threat-intel firm Defused Cyber observed exploitation of CVE-2026-55040 (CVSS 9.1) in SharePoint honeypots the day after Rapid7 published its PoC (Aug 11). The authentication-bypass flaw, patched in Microsoft’s July update, is the first half of a two-part chain — completed by August-patched RCE CVE-2026-63520 — that reaches unauthenticated remote code execution. CISA had warned of SharePoint-targeting exploit activity in July, and Resecurity flags this chain as a likely vector. Organizations that have not applied the July SharePoint patches should treat this as actively exploited. 🔗 Reference: The Hacker News | iThome
📌 WordPress “XSS2Shell” flaw: CVE-2026-64638 (CVSS 8.9) in the login page — Researchers at pwn.ai disclosed a reflected XSS in the WordPress login page affecting all versions with no authentication required: a crafted username is reflected after a failed login and executes in the victim’s browser. Under additional conditions — an admin logged in and interacting with an attacker-controlled page — the researchers demonstrated escalation to arbitrary PHP code execution on the server with a single click. 🔗 Reference: xakep.ru
📌 Apple emergency-patches macOS Screen Sharing: CVE-2026-65400 (CVSS 7.1) — In a rare out-of-band update on Aug 6, Apple shipped macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 to fix a Screen Sharing flaw letting remote attackers bypass authentication without valid credentials. Huntress attributes the bug to a state-management error in the service’s Secure Remote Password (SRP) verification, enabling a pre-auth bypass that can lead to remote code execution; because Screen Sharing runs as root, the impact can be root-level. No in-the-wild exploitation is confirmed, but Huntress and Calif researchers reproduced the flaw and published a PoC. 🔗 Reference: iThome | JPCERT/CC
📌 Jewelbug: China-based hackers-for-hire run espionage and crypto fraud from one panel — Symantec Threat Hunter Team details Jewelbug, a China-linked group whose single control panel (XG-Web, a browser-centric remote-access framework) administers both espionage against government ministries in the Middle East, Southeast Asia, and South Asia, and an industrial-scale cryptocurrency fraud business. The main implant is the Antino backdoor, paired with a malicious “PDF Viewer” Chrome/Firefox extension and an Edge helper; one watering-hole script hit 15+ government webmail tenants in a single Middle Eastern country. In under three months the victim database logged over 1 million implant check-ins and 580,000+ stolen browser cookies. At least one operator is tied to a registered Hunan company. 🔗 Reference: Symantec | Dark Reading
📌 “BH Alert” Android spyware masquerades as a Bahrain civil-defense app — Security firm Dream uncovered BH Alert, Android spyware distributed during the Middle East conflict via a fake Google Play page impersonating Bahrain’s civil defense and government, complete with fake reviews and download counts. The multi-stage chain deploys the OctagonPanel RAT — SMS interception, contact harvesting, screenshots, credential theft, banking-app phishing overlays, and remote control — and abuses Accessibility Service permissions for persistence. Russian-language traces suggest a Russian-speaking developer; no attribution yet. 🔗 Reference: iThome
📌 Signal adds automatic key verification with Key Transparency — Signal introduced automatic key verification backed by a Key Transparency log so contacts’ public keys can be checked against the historical record, reducing man-in-the-middle risk without manual Safety Number comparisons. Cloudflare and Trail of Bits act as independent auditors. Limits: it confirms key-to-identifier consistency, not current account control, and requires a phone number. 🔗 Reference: iThome
📌 Exchange Server: 7 flaws in August update, top CVE at CVSS 8.8 — August Patch Tuesday included 7 Exchange Server vulnerabilities (privilege escalation, denial of service, spoofing, RCE) affecting Exchange 2016, 2019, and Subscription Edition. The most severe is CVE-2026-62913 (CVSS 8.8), a heap buffer overflow leading to RCE; CVE-2026-62911 (CVSS 8.0) is a privilege-escalation flaw. Microsoft also notes the August update disables the legacy Outlook Web Access Light (OWA Light). 🔗 Reference: iThome
📌 Belgium eID: Connective Signing Extension flaws enable PIN theft and drive-by RCE — Have I Been Pwned researchers found the Connective Signing Extension — used by 2M+ Belgians for eID cards and Maestro payments — failed to bind requests to their originating website, letting malicious sites, ads, or hidden iframes replay activation tokens, read card data, steal eID PINs, forge signing requests, and execute code on Windows devices. The flaws (now patched) also allowed attacker-controlled PIN dialogs impersonating banking and government services; qualified signatures carry the same legal weight as handwritten signatures across the EU. 🔗 Reference: CyberSecurityNews | Dark Reading
📌 RISC-V processors confirmed vulnerable to Spectre; Linux mitigations found ineffective — Researchers from CISPA and KU Leuven (USENIX Security 2026) tested commercial RISC-V CPUs — SiFive P550 and T-Head C910/C920 — and reproduced 12 of 13 Spectre attack scenarios, including a kernel-memory read demo on the C910 (median 338 bytes/sec via BPF). They found Linux’s barrier_nospec() compiles to a no-op on RISC-V and the BPF JIT emits no speculation barrier, leaving defenses ineffective. Three of five proposed kernel patches are merged; a dedicated speculation-stopping instruction is still missing from the ISA.
🔗 Reference: iThome
📌 OMB rewrites federal logging policy (M-26-14), extends scope to IoT/OT — The US Office of Management and Budget memo M-26-14 (May) replaces the 2021 M-21-31: agencies now decide which logs to collect and retain based on mission and risk rather than mass collection, aiming for logs that actually support threat detection, hunting, and investigation. The policy explicitly extends logging scope to IoT and OT environments and introduces a log maturity model enterprises can borrow from. 🔗 Reference: iThome