AI benefits/risks

The Taiwan attack was built with two free downloads from vendors nobody rates  

(Adobe Stock)

COMMENTARY: Four days. Twenty-one government systems mapped. Eighty-five employee accounts compromised. Roughly 2,500 personnel records exfiltrated. 1,395 operational files generated.

Taiwan confirmed the campaign on August 13, 2026, and researchers at the Israeli cyberdefense firm Dream, who discovered it, say it ran largely on its own.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

Most of the coverage since has focused on what the tool did, and the numbers earn that attention. I want to talk about what it was made of, because that part has gotten almost no coverage at all, and it’s the part every enterprise running AI agents needs to focus on.

Dream says the tool was assembled from two open-source AI agent frameworks, the same category of free, downloadable components that security and engineering teams are shipping into production right now. It coordinated as many as eight sub-agents at once, each assigned a function: reconnaissance, API enumeration, credential attacks, vulnerability validation, lateral movement, and supply-chain targeting.

When one attack path failed, it adapted and tried another. That’s not a script kiddie tool, and it’s not a nation-state weapons program either. It’s two frameworks anyone can download for free, wired together with enough orchestration logic to run an autonomous, multi-day intrusion against a national government. That combination changes the proliferation math for offensive AI more than any single headline number in the Dream report.

One detail matters more than it has been given credit for: the tool went after Taiwan's IT supply chain vendors specifically, alongside the nuclear safety agency, at least seven energy companies, and a government email system. Supplier concentration was not incidental to this attack. It was part of the design.

So here is the exercise I would ask any CISO or board member reading this to actually do: Open the organization's agent stack and name every framework in its dependency tree. Not the model vendor, the frameworks underneath it, the open-source orchestration layer that decides what an agent can reach and what it can do once it is inside. Most people cannot get past the first name. That’s not a knock on any single security team. It’s a description of an entire supplier category that has never been mapped, rated, or run through procurement, because it does not arrive as a purchase. It arrives as a dependency.

And, it’s not a one-off: two weeks before Taiwan went public, CrowdStrike reported that a North Korea-nexus group was found injecting a malicious dependency into at least 131 packages of a different, widely used AI agent framework. That was the supply side of the same layer, poisoning the tools before anyone even used them.

Taiwan is the offensive side, tools built from the layer and pointed outward. Two incidents, two weeks apart, two different attackers, one unmapped layer connecting them.

Separately, researchers have reported this week that AI-powered hacking tools are now for sale in underground forums, which tells us how little time we have between a capability demonstration like this one and its arrival as a commodity.

I want to be precise here, because it’s the kind of story where it’s easy to overreach. I am not claiming my team would have flagged this specific tool in advance, and I am not claiming anyone rates every open-source package that ships inside an agent framework. Nobody does that today, including us.

I’m arguing something narrower, and I think more useful: the agent-framework layer represents a real supplier category, it has now demonstrated real offensive utility twice in a month, and it has zero independent coverage. No analyst chart includes it, because its suppliers are open-source projects and small companies that do not run briefing programs for analysts. No ratings service scores it. No procurement standard treats it as a vendor relationship at all, even though production systems now depend on it the way they depend on an operating system.

It makes sense to write about this gap regardless of who eventually closes it. We cannot rate a supply chain we have never mapped, and almost nobody has mapped this one. Think of Taiwan as the version of that problem with a forensic report attached to it. The version sitting inside our own agent stack right now does not come with one, and it will not, until someone decides that an open-source dependency tree is a vendor list like any other and starts treating it that way.

So ask that question inside the company’s own walls before someone else forces us to answer it in public: Which agent frameworks are running in our stack? Who built them? And, who, if anyone, has ever rated them?

Most executives can name the first one. Almost nobody I've talked to can answer all three. Until this layer gets mapped the way every other vendor list gets mapped, it will keep looking exactly like it looked in Taiwan: wide open, and free to build.

Rob Smith, founder and CEO, Lionfish Tech Advisors

SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

Rob Smith

Rob Smith is the CEO of Lionfish Tech Advisor.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds