$ 45 € 51.21 zł 11.68
+11° Kyiv +12° Warsaw +19° Washington

AI agents lower barriers to cyberattacks — Daily Maverick

Lev Shevtsov 21 September 2026 00:10
AI agents lower barriers to cyberattacks — Daily Maverick

In Taiwan, AI agents mapped 21 government systems in four days, gained access to 85 accounts, and extracted 2,500 personnel records. This is stated in a Daily Maverick column, whose author writes that autonomous systems make it possible to scale vulnerability discovery without large teams of specialists.

Vulnerability scanning

According to Taiwan’s Ministry of Digital Affairs, the agents exploited vulnerabilities in secondary systems. The column’s author notes that outdated equipment, unpatched software, forgotten APIs, network devices, and systems with default passwords could have remained unnoticed for a long time not because of robust protection, but because people had limited capacity to find and exploit such weaknesses.

The column also cites an example of a data extortion campaign in August 2025. According to the author’s description, one criminal with limited technical skills attacked 17 organizations over the course of a month, assigning an AI agent to scan VPN nodes, infiltrate networks, collect credentials, and draft personalized ransom letters demanding up to $500,000. Anthropic’s threat intelligence team called this approach “vibe hacking.”

More current news is available on the UA.News Telegram channel Telegram.

Automation of attacks and defense

The author also mentions the GTG-1002 group, which is tracked as being supported by China. According to him, it used Claude Code against around 30 commercial and defense targets. At the beginning of 2026, Amazon’s threat analysis unit, as stated in the column, identified one actor that attacked internet-accessible perimeter infrastructure in 55 countries. The actor combined Claude and DeepSeek models in an automated system that read management interface responses and selected exploitation paths.

In the author’s view, defenders are in a more difficult position because an attacker may need only one vulnerable component, while system owners must protect all access points. Among possible approaches, he names a zero-trust architecture, under which internal interactions are verified, as well as moving-target defense — continuously changing execution environment parameters so as not to leave attackers with a fixed target.

Read us on
Download our app