Slashdot

News for nerds, stuff that matters

China-Linked Hackers Used AI To Run First-Ever 'Autonomous' Cyberattack On Taiwan

Researchers at Israeli cybersecurity firm Dream say suspected China-linked hackers used an open-source AI-agent system to conduct what may be the first observed end-to-end autonomous cyberattack against a government. According to the Financial Times (paywalled), the attack compromised at least 85 accounts and resulted in the theft of more than 2,500 personnel records from Taiwanese systems. Tom's Hardware reports: The campaign reportedly ran for four days at the beginning of July and at times deployed as many as eight autonomous agents in parallel. Dream said the system mapped 21 government systems before compromising user accounts and extracting personnel information. The attackers subsequently expanded their activity to Taiwan's nuclear safety agency, at least seven energy companies, government suppliers, and other government systems.

Dream says it found the evidence inside a 160-megabyte (160MB) online archive that surfaced during its broader tracking of cyberthreat actors. The archive reportedly held 1,395 files showing that the tool was built on two open-source AI agent systems -- Hermes and OpenClaw -- both of which can be downloaded freely and are designed to let large language models carry out multi-step tasks on their own.

Researchers could not determine which underlying model powered the agents, but the data reportedly showed the model's safeguards had been sidestepped by presenting the intrusion as an authorized penetration test rather than a real attack. Of particular concern is that the toolkit for the hack comprised such easily available systems, neither of which was purpose-built for offense. The operators appear to have assembled a capable autonomous tool out of components any developer can pull down and run.

What the researchers describe as the tool's most striking feature was its ability to continuously devise attacks on its own, rather than follow a preprogrammed route. The platform continuously assessed available evidence, ranked possible attack paths, and reprioritized them as circumstances changed. When one technique failed, the tool tasked another agent with searching the internet for information and developing an alternative approach.

Read more of this story at Slashdot.

MetaFilter

The past 24 hours of MetaFilter

I bought a Billboard for a Fake AI that's Just me

A meaningless tier to help me pay off that billboard In this YT short Tucker Bryant briefly explains his project. A 32-year-old former Google employee who describes himself as a conceptual artist and keynote speaker, Bryant is the one-man operation behind San Francisco's latest viral billboard, a 14- by 48-foot ad on the corner of Sixth and Folsom streets that reads "ChatTJB: The leading chat interface powered by AI." The twist: AI in this case stands for "Average Individual." TJB are just Bryant's initials. And the chatbot isn't powered by a large language model but by Bryant's weary brain and tired fingers. Source The San Francisco Standard

Here a link to his previous art projects How he describes his work as a Poet/Artist: I break patterns on purpose so better outcomes can emerge. I learned how to do that during a decade in Silicon Valley—studying at Stanford University and working at Google—where innovation is less about inspiration and more about structure. You test assumptions. You design constraints. You build before certainty arrives. At the same time, I started applying that mindset to an old form of art that I loved, but that lots of people feel like they don't "get." Instead of treating poetry as words on a page that captivate bookworms but leaves lots of others scratching their heads, I wanted to treat it as an experience to be designed. Timing, environment, interactivity, friction—the medium became what I obsessed over innovating on. Source Tucker Bryant About

March on Washington: Defend the Vote // Friday, August 28th in DC

Set your calendars! There will be a new "March on Washington" on August 28. Sponsored by the Rev. Al Sharpton, Martin Luther King III, and a coalition of civil rights groups, marchers will gather at the Lincoln Memorial to demand voting rights — in the face of the ongoing Republican assault on fair representation — and economic justice.

The march is being organized around the 63rd anniversary of the original 1963 March, at which the Rev. Martin Luther King Jr. delivered his "I Have a Dream" speech. Find out more about the event at MarchonWashington2026.com, where you can register to attend, sponsor a bus to the event, organize on behalf of a religious congregation, or partner with march organizers. "We stand on the same ground because the work is not finished," Sharpton said in announcing the new march. "The dream was never a memory to admire," he added. "It was an assignment to complete." MARCH ON WASHINGTON 2026 BUS INTEREST FORM: https://actionnetwork.org/forms/march-on-washington-2026-bus-interest-form/ This is our moment to show up, stand together, defend the vote, and build power for the people. We hope to see you there! More at the website: https://marchonwashington2026.com/

Paint that has lasted 2000 years

Scientists have analyzed paint from the 2000 year old Huashan Rock art and think they've discovered the secret behind it, blood, specifically post partum blood.

Goth chemists and artists, this is your time to shine!

Wel.nl

Minder lezen, Meer weten.

Grote fondsen in nieuw stelsel voorzien kleine pensioenverhoging

DEN HAAG (ANP) - Gepensioneerden van de grote pensioenfondsen die al zijn overgestapt naar het nieuwe pensioenstelsel, kunnen volgend jaar mogelijk een bescheiden pensioenverhoging tegemoetzien. Dankzij positieve rendementen hebben Pensioenfonds Zorg en Welzijn (PFZW), Pensioenfonds Metaal en Techniek (PMT) en bpfBOUW hun financiële situatie in het tweede kwartaal duidelijk verbeterd.

Volgens voorlopige inschattingen van PFZW en bpfBOUW kunnen de uitkeringen straks met ongeveer 0,6 procent worden verhoogd. Metaalfonds PMT gaat op basis van de financiële situatie per eind juni uit van een plus van 0,5 procent. Het gaat wel om een indicatie of momentopname. De daadwerkelijke gevolgen voor pensioenuitkeringen in 2027 worden pas bepaald op basis van de cijfers per eind september.

In het eerste kwartaal ondervonden de fondsen nog fikse hinder van de oorlog in het Midden-Oosten en een gedaalde rente. De pensioenopbouw van bij elkaar miljoenen deelnemers liep hierdoor schade op. In het tweede kwartaal ging het financieel beduidend beter met de fondsen.

Recordstanden aandelenmarkten

Dat is vooral te danken aan recente recordstanden op de aandelenmarkten, mede door het grote enthousiasme bij beleggers over kunstmatige intelligentie. Techbedrijven en chipfondsen zijn daardoor flink in waarde gestegen. Ook is de onrust op de beurzen over de oorlog in het Midden-Oosten wat afgenomen.

"De beleggingsresultaten over dit kwartaal zijn positief, waarbij met name de aandelenrendementen er positief uitspringen", zegt Caspar Vlaar, voorzitter namens de werknemers en pensioengerechtigden bij PMT. "Daarmee is het negatieve effect uit het eerste kwartaal voor de meeste deelnemers grotendeels ingehaald. De verschillen tussen het eerste en tweede kwartaal laten goed zien dat deze resultaten momentopnames zijn."

Buffer

Door de overgang naar het nieuwe pensioenstelsel gingen de pensioenen bij de drie grote fondsen begin dit jaar nog fors omhoog. Dat kwam omdat toen een deel van de buffer werd verdeeld. Zo'n grote verhoging lijkt er volgend jaar hoe dan ook niet in te zitten.

Van de grote fondsen zijn ambtenaren- en onderwijzerspensioenfonds ABP en metalektrofonds PME nog niet over naar het nieuwe stelsel. Zij kwamen vorige maand al met hun kwartaalberichten. ABP hintte erop dat deelnemers van het grootste pensioenfonds van Nederland straks mogelijk een extra pensioenverhoging kunnen verwachten. ABP gaat komende jaarwisseling over naar het nieuwe stelsel.


The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

'Near-autonomous' AI agents attack Taiwan's nuclear safety agency

Suspected Chinese cyber operatives used publicly available AI tools to compromise Taiwanese government systems before expanding the attack to its nuclear safety agency, supply-chain vendors, and at least seven energy companies in what security researchers called a "near-autonomous attack." Over the first four days of July, AI agents compromised 85 government user accounts and extracted more than 2,500 personnel records, according to Dream, an Israeli cybersecurity firm. Researchers uncovered evidence of the attack in a 160 MB online archive containing 1,395 files documenting the operation. Dream, in research published on Wednesday, detailed the intrusions and said that the suspected Chinese hackers hit “government entities in Asia” - but declined to say which government had been attacked. A person familiar with the attack confirmed to The Register that Taiwan was the target. The Financial Times first reported on Dream’s research and identified Taiwan. While the security firm doesn’t attribute the agentic attack to the Chinese government or a specific hacking group, the operational documentation “points to a Chinese-language operator,” the researchers said. According to Dream, the attack framework, built on open source Hermes and OpenClaw AI agents, deployed up to eight sub-agents, each assigned to its own targets and attack techniques, across 12 “attack waves” between July 1 and July 4. First, the agents mapped the entire government ecosystem, extracting embedded URLs, API endpoints, OAuth client IDs, and Keycloak configuration objects from a single government portal. This portal allowed the agents to identify 21 connected government systems and every supported authentication flow. “On one target alone, it discovered 36+ API endpoints spanning account management, user data retrieval, file upload, and administrative functions - many completely unauthenticated,” the Dream threat researchers wrote. “Critically, it found that one of the systems exposed its entire user database without any authentication - thousands of employee records including names, departments, and SSO account IDs.” Multiple entry points After mapping the government’s attack surface, the agents found multiple entry points including three hidden API endpoints that accepted any request body and returned a valid authenticated session without requiring user credentials. Using employee usernames harvested from an unauthenticated API, the agents broke into a government department’s office automation portal, solving its CAPTCHAs with 100 percent accuracy. The agents also tested predictable password patterns based on each employee’s ID, and cracked 85 accounts across multiple password-spray rounds. Eighty-four of the 85 cracked accounts successfully authenticated to the department's internal information system, giving the attackers access to internal dashboards, equipment management interfaces, and personnel statistics pages. In total, the illicit access allowed the agents to exfiltrate a ton of government information, including more than 2,564 personnel records, a full JSON export of all department system users, seven SSO client secrets, six internal database credentials across MSSQL, Oracle, and Sybase, and internal network IP ranges. But wait, there's more And then, the agents pivoted to the Taiwanese government’s supply chain. “It expanded the operation to government IT supply chain vendors, a nuclear safety agency, a government email system, and 7+ energy sector companies - scanning them all in parallel for misconfigurations, exposed admin interfaces, and exploitable vulnerabilities,” the researchers wrote. Notably, the attack framework implemented what the AI tools called “learning cycles.” These are autonomous sessions where the models search vulnerability databases, GitHub repositories, and other security research for specific techniques, CVEs, and common weaknesses to exploit in the targeted government's infrastructure. Additionally, when the AI framework made a mistake, it “self-corrected,” according to Dream, catching errors and fixing them through its own verification process. This near-autonomous attack comes as frontier model makers OpenAI, Anthropic, and Meta all admitted that their agents went rogue, escaped from their training environments, and autonomously hacked other organizations and people. OpenAI technical staffer Michael Dalton, in a Black Hat briefing last week about the Hugging Face attack, said “AI orchestrated, fully automated offensive attacks are real now.” “In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that you have just described here,” he added. It appears that the future is now. ®

Tailscale says deeply buried 16-year-old SQLite bug caused last year's outages

Users of peer-to-peer networking outfit Tailscale might have struggled through some surprising outages beginning late last year. After a six-month investigation, the team finally knows why: A bug in SQLite’s write-ahead log that had remained hidden for 16 years. The Tailscale team announced in a Wednesday blog post that it had finally addressed the issue with the help of SQLite maintainers, who even had to create a new tool (with Tailscale funding) to log virtual file system activity in order to track the thing down, which Tailscale software engineer Alex Chan described as resisting “all our initial attempts to find it.” According to Chan, the problem goes deep into the nature of SQLite – so deep that the database maintainers actually had to add code to reproduce it. To understand what happened, it’s necessary to know how Tailscale works. The service, based on the WireGuard VPN protocol, directly connects devices in a virtual private mesh network. It’s designed to be low complexity and easy to implement for everything from remotely accessing a NAS to connecting teams in a unified private network. Each mesh network, or "tailnet," lives on one of several servers, where a SQLite database manages all the information about the tailnets it houses. “We’ve used SQLite as our primary database since 2022, and we chose it because it's well-known, reliable, and widely used,” Chan wrote in the company’s post-mortem. But a year ago, something went very wrong. “In our current backup pipeline, we take a complete snapshot of the database every few minutes, then upload the entire SQLite file to an S3 bucket,” Chan said, but in August 2025 those backups began detecting database corruption, repeatedly, with no obvious common trigger. The Tailscale team couldn’t reproduce the issue because there were no reliable triggers for it. No low-level code had been changed in months. A review of everything that touched SQLite turned up nothing. Working with the SQLite team, the Tailscalers tried to figure out what could be causing it – POSIX locks broken by close() calls? Nope. Mismanaged memory? Not that either. SQLite being used from multiple threads with thread safety disabled? Nuh-uh. “After every incident, we gathered more data, added more diagnostics, and systematically ruled out these theories,” Chan explained. The WAL-Reset bug comes out of hiding Suspicion was closing in on SQLite’s checkpointing process, which is how it takes new database entries out of a temporary hopper for addition to the master database file. SQLite has an option to improve performance and concurrency known as the Write-Ahead Log (WAL), which serves as the aforementioned hopper. Writing the WAL to the database occurs in a process known as checkpointing. “In most deployments, SQLite itself decides when to do a checkpoint, and the process is invisible to the end user and developer,” Chan said. “In our control plane, we take manual control of the checkpoint process so we can run fast and consistent backups.” The SQLite team wrote a new tool to take a closer look at the process: a virtual file system shim that extensively logs checkpointing activity. After waiting for the next corruption incident, the teams had their answer, dubbed the WAL-Reset bug. Described by Chan as “a rare data race in the SQLite source code between a checkpoint and write transaction,” it’s essentially a collision between checkpoints and writing data to the WAL. “If a write occurs at a specific time during a checkpoint, the checkpointing process gets confused — it thinks some of the pages have been copied from the WAL into the main database file, but they haven’t,” Chan said. Those pages are never written and are permanently lost, but pages that reference those pages are still written, corrupting the database and causing all hell to break loose. According to the SQLite team’s WAL-Reset writeup, the issue can be triggered only when WAL mode is active and multiple database connections are open on the same file, and because there has to be reading and writing going on at the same memory spot at the same time, it’s incredibly unlikely to happen in most situations. Tailscale’s decision to perform manual checkpoints was a rare exception. SQLite maintainers believe the bug was present going all the way back to version 3.7.0, released in July 2010; it’s now fixed, and the SQLite team recommends users update to a fixed version, though it stresses the bug is extremely unlikely to occur in ordinary use. “This bug, though rare, does have serious consequences,” the SQLite WAL-Reset notice states. The incident contains a useful reminder for devs: Even the most boring, reliable software poses risks when operated in a non-standard fashion. “Most people use SQLite in a standard configuration and never face this sort of issue,” Chan said. “By taking manual control of the checkpointing process and running at our own aggressive pace, we stepped off the well-trodden operational path.” ®

Behance Featured Projects

The latest projects featured on the Behance

Johnny Knoxville for the New Yorker


The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Israeli militants besiege two Palestinian families in their West Bank homes

Settlers and soldiers cut off water and electricity to homes, and block medical care in campaign of terror

Israeli militants have besieged two Palestinian families in their homes since the weekend, aiming to take over their properties in the West Bank village of Qusra through a campaign of terror.

A group of settlers and soldiers set up a tent outside the home of Yousef Hassan on Sunday afternoon, trapping him inside with his wife and two young daughters.

Continue reading...

Blossoms and puddles: Hiroshima

billy.reeder has added a photo to the pool:

Blossoms and puddles: Hiroshima

A quiet,rainy stroll beneath the pink,vibrant petals.