Autonomous AI agents hacked the Taiwan government in a cyber first
Suisun City cyberattack recovery could take months, Microsoft patches 400 flaws, three zero-days, $100 device can hijack Boeing 737 systems, Hackers hijack AnMed Facebook page with ransom demands, German lawmaker urges cyber strikes on Russian drone factories, much more

Check out my latest CSO piece, which explains that it's not security flaws of AI models that necessarily pose the biggest threat – it's the software that surrounds those models, or "the harness," that organizations should prioritize.
Metacurity is the cybersecurity news you'd need hours to assemble yourself.
Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.
A paid subscription to Metacurity delivers
- Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
- Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
- Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.
Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.
Please consider supporting us. And thank you!
According to researchers at Dream, an Israeli AI and cybersecurity company, suspected Chinese hackers used publicly available AI tools to compromise government websites in Taiwan in a first-of-a-kind breach, highlighting how artificial intelligence is transforming cyber warfare.
The attackers used open-source AI agents to build an autonomous hacking tool that behaved like a coordinated cyber team.
Over four days at the start of July, the tool simultaneously deployed up to eight autonomous agents that mapped 21 government systems, researched vulnerabilities, and changed tactics when blocked.
The tool compromised at least 85 government user accounts, extracting more than 2,500 personnel records before expanding the attack to Taiwan’s nuclear safety agency and at least seven energy companies, the research showed.
The discovery comes as the AI and cyber industries wrestle with the ability of the latest models to identify and exploit software vulnerabilities. Anthropic, OpenAI and Meta have also reported new AI models launching unexpected cyber attacks during testing.
Dream’s chief strategy officer, Amir Becker, who previously headed cyber operations for Israel’s elite signals intelligence Unit 8200, said he had never before seen such an “end-to-end autonomous attack” on a government target.
The advent of AI tools meant governments must now assume they are under permanent cyber attack, he added, saying: “This must be the basic assumption of every government around the globe.”
A person with knowledge of the attack said the target was Taiwan. Dream declined to confirm the identity of the targeted government, citing company policy, but said it had informed a country in “Asia-Pacific” of the breach.
Dream has not attributed the attack to a specific group, but researchers said the use of Simplified Chinese in internal communications linked to the hack meant there was a high probability the operator was connected to China.
In contrast, the data recovered from the target was written in Traditional Chinese, as is common only on government websites in Taiwan, Hong Kong and Macau. (Tom Wilson / Financial Times)
Related: Dream, National Technology News, Benzinga, Fudzilla, Clash Report, Dev.ua, Startup Fortune
Fixing SuiSun City's IT network, following a cyberattack, will not be quick, City Manager Bret Prebula said at an early morning City Council meeting on Tuesday.
There is no conclusion yet, Prebula said, on whether personal information of Suisun City residents is at risk.
Prebula estimated that, hopefully, it would be fully restored around Halloween.
In the interim, City Hall is closed for the remainder of the week as employees work from home so they can access the Cloud.
Prebula said the current operation is at about a 1995 level. Some tasks that may only take 20 minutes are now taking longer.
In an emergency closed-session meeting on Tuesday, the City Council discussed how they would respond to a demand from an unknown number of perpetrators behind the cyberattack. The results of the meeting were not immediately made available.
The city declared a state of emergency after malicious software initially infected city systems the morning of Aug. 7 and impacted 911 routing, police and fire dispatch, and city services, leading the city to shut down its IT system, according to the Suisun City municipal website. (Amy Maginnis / Daily Republic, Chrissa Olson / San Francisco Chronicle)
Related: KRON4, Daily Republic, SF Gate, KION
For its August Patch Tuesday fixes, Microsoft issued security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities.
The software giant addressed 42 "Critical" vulnerabilities, 37 of which are remote code execution and 5 are elevation of privilege.
This month's Patch Tuesday fixes three zero-day vulnerabilities, with one exploited in attacks and two publicly disclosed. The active exploited zero-day vulnerability addressed is CVE-2026-68820 - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability,
The two publicly disclosed zero-days that were fixed are CVE-2026-62832 - Windows User Profile Service Elevation of Privilege Vulnerability and CVE-2026-72971 - Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability.
Other vendors who released updates or advisories in August 2026 include Adobe, Cisco, Metabase, N-Able, SAP, TP-Link, and VMware. (Lawrence Abrams / Bleeping Computer)
Related: Reddit - Information Security News, Bleeping Computer, Redmond Magazine, Security Week, Tenable Blog, Help Net Security, Neowin, Krebs on Security, Security Affairs, Dark Reading, The Register, Qualys, Thurrott, Forbes, Rapid7, SANS Internet Storm Center, Ask Woody, Infosecurity Magazine, CSO Online, Cisco Talos
At the Usenix Cybersecurity Conference, researchers from the University of California at San Diego and Oberlin College will present a hacking technique capable of commandeering the autopilot of a Boeing 737 to redirect its navigation or silently altering key values in the plane's takeoff and fuel calculations while spoofing the results on the pilot's screen—subtle changes the researchers say could potentially cause anything from runway overruns on takeoff to diversions to a different country's airspace to catastrophic crashes.
To carry out that hacking, they've built a roughly coin-sized, Wi-Fi-enabled prototype device that costs less than $100. In less than a minute, that hardware implant can be fitted into a port accessible via a hatch on the exterior of the plane, one that's routinely within reach of maintenance workers or other airport and airline staff between flights. Once it's in place, the device can send electrical signals on one of the 737's internal networks to spoof commands to sensitive computer systems that guide its autopilot and show the pilot variables like the plane's total weight and outside air temperature, which play a critical role in a 737's takeoff calculations.
By proving the viability of that technique, the result of a process that stretched over more than a decade and entailed buying tens of thousands of dollars’ worth of plane components for testing, they hope to show that this sort of physical access hacking represents a practical threat in the hands of well-resourced saboteurs and a significant blind spot in aircraft security. Compared to the traditional threat of simply planting a bomb on a plane, they argue, it's also an approach that would offer an attacker more control, stealth, and deniability. (Andy Greenberg / Wired)
Related: USENIX Security Symposium

Two weeks after a cyberattack knocked out its IT systems, the nonprofit medical system AnMed is still facing closures and the apparent hack of its Facebook page, which on Tuesday began showing ransom demands from the purported hackers.
The social media page for the medical chain, which has four hospitals and other clinics in Georgia and South Carolina, was removed from Facebook shortly after a series of messages claiming to be from “The Gentlemen” ransomware group appeared.
The hackers claimed to have exfiltrated 6 terabytes of data, including highly sensitive health information like records related to sexual assault, mental health, abortions, and sexual harassment incidents. They did not provide any evidence to back up these claims. On its website, AnMed still says it has not “confirmed the scope of any potential impact to patient information,” nor have they said if patient information was affected.
"Earlier today, AnMed identified unauthorized posts on its social media accounts. The unauthorized content was removed, access through the platform was disabled, and we are working with the provider to secure the accounts," a spokesperson said in a statement, adding that the claims contained in the posts have not been verified. "AnMed and its cybersecurity specialists are investigating the matter as part of the organization’s ongoing response to the cybersecurity incident identified on July 26." (James Reddick / The Record)
Related: Anmed, WSPA, WYFF, Independent Mail
Marc Henrichmann, chairman of Germany's Bundestag’s Parliamentary Control Committee, said he wants to empower German intelligence services to launch preemptive cyber strikes against Russian drone manufacturers.
This is part of the intelligence service reform he is currently helping to prepare. "Pure intelligence gathering" will no longer suffice, Henrichmann emphasized. The best drone, he said, is the one that never takes to the air and thus never threatens human lives in Germany.
Speaking on the news channel WELT TV, Henrichmann said: "We really need to empower our services so that, ideally, they can disable and neutralize the attack drone in Russia, or the factory that manufactures it, before it can target a German airport or endanger the safety and lives of people in Germany." He added that the services need to be "restructured and reorganized, ideally getting ahead of the threat." "The best drone is the one that never takes off and can threaten Germany," Henrichmann continued. (Welt.de)
Related: Reuters, Ukrainska Pravda, United24, Liga, RBC-Ukraine, UA News, Wall Street Journal, Kyiv Post
Cyberattack attempts targeting South Korea’s Overseas Koreans Agency surged to 4,271 in the first seven months of this year, more than 12 times the 353 attempts recorded throughout last year, according to data released by the agency.
The agency, launched in June 2023, has yet to establish a dedicated cybersecurity unit and only began allocating a separate information security budget this year.
According to cybersecurity management data submitted by the Overseas Koreans Agency to the office of Rep. Kim Gunn of the main opposition People Power Party, attempted cyberattacks on the agency totaled 221 between its launch on June 5, 2023, and the end of that year.
The number rose to 748 in 2024 before falling to 353 last year. From January through July this year, however, the figure jumped to 4,271.
Website hacking attempts accounted for the largest share this year, followed by 1,547 cases involving blacklisted IP addresses, 352 denial-of-service attempts, 64 unauthorized access attempts, and 60 network intrusion attempts.
There were also five attempts to collect server information, four malware infection attempts and three attempts to exfiltrate server information. (Choi He-Suk / The Korea Herald)
Korean telecom giant KT's quarterly operating profit extended a losing streak as costs related to the fallout from last year’s user data breach continued to weigh on its core businesses.
The company's second-quarter operating profit fell 36.1 percent year-on-year to 648.3 billion won ($457.3 million) on a consolidated basis, according to the company on Wednesday. Revenue fell 10.1 percent year to date to 6.68 trillion won in the same period, while net profit declined 34.5 percent to 480.6 billion won.
On a standalone basis, the telecom posted operating profit of 389 billion won, down 17 percent during the same period. (Korea JoongAng Daily)
Related: The Chosun Daily, Yonhap News, Maeil Business, Seoul Economic Daily, Asia Business Daily, Digital Today
Uber Freight is investigating a data security incident involving unauthorized access to a portion of its systems and repositories, a company spokesperson said.
There has been "no impact to Uber Freight's business operations, which continue in the normal course without disruption," spokesperson Sam Hallock said. "Our systems are secure and fully operational."
A hacking group going by the name "Helix" posted to its website on August 6 what it claimed was nearly 1 million Uber Freight files. Hallock did not comment on whether the data posted by the hackers was authentic, when the company was informed by the hackers of the breach, or whether the company interacted with the hackers.
Helix is one of several names associated with a cluster of high-profile hacking activity targeting a wide swath of major companies, Google Threat Intelligence said in an August 6 blog post.
Companies targeted as part of the campaign include Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody's, as well as other businesses. (AJ Vicens and Raphael Satter/ Reuters)
Related: Big Go Finance, The Next Web
Global supply chain and distribution giant Wesco has confirmed in a statement that it is investigating a cybersecurity incident.
The company's statement comes after data extortion group ExfilSquad claimed to have stolen sensitive information from Wesco and leaked it on their data leak site.
Jennifer Sniderman, Vice President of Corporate Communications at Wesco, said that the incident involves the company's cloud CRM environment.
The company representative added that Wesco has not experienced any business disruption, and all operations continue as normal.
Wesco said the incident was detected quickly, and its subsequent investigation found no evidence of ransomware or other malicious software on its IT systems. (Bill Toulas / Bleeping Computer)
Related: SC Media

According to Microsoft, the DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity.
The threat actor emerged in mid-2025 and uses double-extortion tactics (data theft/leak and file encryption) to pressure victims into paying a ransom.
By July this year, DeadLock's data leak site listed 80 organizations, mostly from Europe. Victims include companies in the IT, mining, transportation, manufacturing, hospitality, and consumer goods sectors.
Microsoft researchers observed the malware being deployed by multiple groups, including an affiliate previously linked to the Lynx and INC ransomware ecosystems.
The DeadLock ransomware operators adopted a new approach that uses the Polygon blockchain to store configuration data and the posts on the leak site.
Instead of using a traditional Tor URL, the HTML page retrieves the current chat-proxy address in a now-common tactic of querying a smart contract on the Polygon blockchain through a read-only eth_call. (Bill Toulas / Bleeping Computer)
Related: Microsoft, Techzine, Tech Times

LawCare, a UK-based mental health and wellbeing charity for the legal sector, said that copies of its database have been duplicated and are likely to have been downloaded by hackers.
The organization is one of more than 1,000 charities that use the software company Beacon CRM, which has been subject to a ‘cyber security incident’.
Beacon is the system LawCare uses to manage information about callers, supporters, donors, volunteers and fundraising contacts. An unauthorized third party may have therefore stolen details of any lawyer who has contacted LawCare. None of the records contain bank account numbers, sort codes, card numbers or card security details, the charity stressed.
In a statement this afternoon, the legal charity said: "Beacon’s investigation into the incident, supported by external cyber security specialists, has confirmed that copies of database backups were made and likely downloaded by the unauthorised third-party. They recommend that we may want to assume that all data that we store in Beacon, including attachment files, have been downloaded."
LawCare added: "We understand that this news may be worrying, and we are very sorry that information people have shared with us may have been affected." (John Hyde / The Law Society Gazette)
Related: Canadian Lawyer Magazine, The Global Legal Post
Researchers at Palo Alto Networks report that the developers of a notorious botnet known as Kimwolf or Aisuru that’s powered mostly by hijacked Android TV boxes and other internet-connected devices have released a new version built to blend attack traffic in with ordinary web browsing and to keep its command channels from being seized by law enforcement.
Palo Alto's Unit 42 said the newest version has been active since February, a month before authorities seized infrastructure powering previous versions of the botnet.
The biggest change is a new flood method built on HTTP/2, the protocol that carries most web traffic today. A flood is the crude heart of a DDoS attack: thousands of infected devices send a target far more requests than it can answer.
Rather than firing raw packets, this latest Kimwolf version operates with full browser fingerprints, copying the header order and behavior of the Chrome web browser. That matters because the usual defense against a flood is for tools to spot the fake traffic and drop or block it before it reaches the server. Traffic that looks like Chrome does not get dropped, so a site under attack must either serve every request and fall over, or start turning away the customers it cannot tell apart from the bots.
The second biggest change looks like it was done to withstand further takedowns. Every bot has to ask a command server for orders, which is also what authorities aim to disrupt in botnet takedowns. Normally, the command server address sits inside the malware as a web domain name, so investigators who take that name from its registrar are able to disrupt an entire botnet. (Greg Otto / CyberScoop)
Related: Palo Alto Networks, Security Affairs
Google says Chrome's anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026.
Google argues that notification abuse has increasingly been used to distribute scams, malware, phishing attempts, and fraudulent payment requests.
To reduce the abuse, Google developed a "Swiss cheese" defense model, where several overlapping systems try to stop abuse at different stages. (Mayank Parmar / Bleeping Computer)
Related: Google Security, Help Net Security, Android Authority

The National Institute for Standards and Technology is looking for input on how to overhaul its vulnerability reporting process to meet better the challenges of an “evolving cybersecurity landscape increasingly shaped by artificial intelligence and machine-consumable security data.”
In a request for information published in the Federal Register, NIST said its National Vulnerability Database, one of the primary ways the federal government coordinates with security researchers to identify and fix software vulnerabilities, must be updated for the AI age.
NIST is concerned that as large language models become more capable of finding and exploiting vulnerabilities at scale, the NVD’s process must be updated.
The agency asked for insight on how defenders could better leverage automation in the vulnerability reporting process; which capabilities, products, and processes would help more quickly disseminate information to stakeholders, how to build transparency and auditability into AI-driven decision-making, and what role AI should play in automated vulnerability remediation. (Derek B. Johnson / CyberScoop)
Related: Federal Register
The federal government has officially ended a ban preventing executive branch employees from downloading TikTok to government devices.
The Office of Management and Budget rescinded the ban in a memo dated Monday and released Tuesday, closing the door on a policy implemented over national security concerns tied to the social media video app’s previous ownership by Beijing-based ByteDance. Congress passed the No TikTok on Government Devices Act in 2022, which required OMB to develop standards for enforcing the app’s ban on government devices.
The change comes after the Justice Department’s Office of Legal Counsel in July determined the ban does not apply to the US version of TikTok created in January by a joint venture that includes Oracle and Abu Dhabi-based artificial intelligence company MGX.
The joint venture was created in response to a law Congress passed in 2024 requiring ByteDance to divest ownership of TikTok or be banned in the US. TikTok temporarily went dark in the US last year, shortly before President Donald Trump paused the law as negotiations for a divestiture deal played out. While Republican China hawks in Congress previously said they would scrutinize the deal to determine whether it complies with the law, they’ve largely accepted it since then. (Aaron Mak / Politico)
Related: White House, Washington Examiner
A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates.
The new vulnerability is described as a bypass for RoguePlanet, another Defender privilege escalation flaw disclosed in June and patched by Microsoft one month later.
However, cybersecurity expert Kevin Beaumont, who also published ShieldBreak exploitation detection queries for Microsoft Defender for Endpoint, said that the two exploits work very differently.
"RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick the quarantine process into overwriting system files," Beaumont noted. "ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API)."
According to Nightmare Eclipse, ShieldBreak can be used to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.
Will Dormann, principal vulnerability analyst at Tharros, confirmed that the exploit works, saying that Microsoft Defender needs to be enabled for the ShieldBreak exploit to escalate attackers' privileges. (Sergiu Gatlan / Bleeping Computer)
Related: Chaotic Eclipse, Security Affairs
Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted.
The new feature is part of a "key transparency" system that uses Cloudflare and Trail of Bits as trusted third-party independent auditors to verify the integrity of Signal conversations.
"It works through a system of verifications performed by you, your Signal connections, and third-party auditors that together provide the same assurance as manually verifying safety numbers. Unlike safety numbers, these verifications are done independently and do not require an in-person meeting or a secondary communication channel," Signal software engineer Katherine Yen said.
Users can enable Automatic Key Verification in Signal by going to Settings > Privacy > Advanced and toggling on Automatic Key Verification. (Sergiu Gatlan / Bleeping Computer)
Related: Signal, The Register, Techaeris, Cyber Insider

Researchers at Check Point report that a new wave of the DPRK-linked Lazarus group’s long-running Operation Dream Job reveals that the campaign now exploits a previously unknown Windows kernel vulnerability to seize full system control while evading endpoint detection entirely.
Posing as recruiters, likely via LinkedIn or direct messaging, the attackers lure victims with fake job offers from well-known companies, ultimately directing them to download malicious files.
Check Point's most alarming discovery is a zero-day local privilege escalation flaw in Microsoft’s AFD.sys driver, which manages Windows socket handling.
The vulnerability is a use-after-free race condition that occurs when concurrent threads access socket state without proper synchronization, granting attackers access to a kernel read/write primitive. (Tamilselvan / Cyber Press)
Related: Check Point, Cyber Security News, NK News

Struggling Boston cybersecurity company Rapid7 said it cut 12 percent of its workforce, or about 300 jobs, in the second quarter.
The cuts, announced alongside the company’s second-quarter earnings report, came as the company’s revenue and profits have been shrinking, and less than a month after the company told the Globe it was laying off only 21 people.
Shares of Rapid7, which were down 35 percent over the past year before Monday’s news, jumped 6 percent in aftermarket trading.
Larger rivals, meanwhile, have been thriving, with fears of AI-powered cybercrooks driving up sales. Shares of CrowdStrike have gained 112 percent over the past year, and Palo Alto Networks’ stock price is up 130 percent. (Aaron Pressman / Boston Globe)
Related: Boston Business Journal, Databreach Today
In its Industrial Ransomware Analysis for Q2 2026, OT cybersecurity firm Dragos revealed a 12 percent increase in ransomware attacks hitting the industrial sector hard, with global impact expected to continue.
“In the second quarter of 2026, analysis of publicly disclosed victim data and ransomware groups’ postings on data leak sites identified 1,140 ransomware incidents affecting industrial organisations worldwide, a 12 per cent increase over the 1,020 incidents recorded in Q1,” Dragos said.
The tactics employed throughout the quarter remained generally the same; exploitation of internet-facing edge devices and remote management tooling, abuse of valid accounts, and credential theft were all in evidence during the quarter.
In addition, ransomware actors are continuing to deploy EDR-killer tooling and bring-your-own-vulnerable-driver (BYOVD) techniques routinely. (David Hollingworth / Cyber Daily)
Related: Dragos, Help Net Security, Security Journal UK

Best Thing of the Day: Finally, Cyber Defenders Might Get the Money They Need
A string of recent AI hacking incidents has created a rush to spend more on cybersecurity as labs race to develop agentic AI from their frontier models.
Bonus Best Thing of the Day: Finally, Protecting the Nation's School Children
The K12 Security Information eXchange has joined the National Council of ISACs, formally connecting the nation’s K-12 education threat information sharing community to the NCI’s network of US government-recognized critical infrastructure-focused Information Sharing and Analysis Centers (ISACs).
Worst Thing of the Day: You Can Comfort Yourself With How Fit You Are Once the World Knows Everything About You
Health obsessives are supercharging their habits by feeding scads of sensitive health data into AI systems.
Bonus Worst Thing of the Day: Taking Corporate Surveillance to Extremes
Wired writer Reece Rogers discovered that McDonald's had built a 515-page dossier on him and had even run predictive algorithms that showed he would never stop eating Big Macs and whatnot.
Closing Thought
