// news · agents2026-08-22source: Black Hat briefings and governance reporting, August 2026

Open-source agents were used in near-autonomous attacks on Taiwan

Security officials at Black Hat confirmed that suspected Chinese operators used open-source agents — Hermes and OpenClaw — against Taiwanese government and energy targets. The significance is not the intrusion. It is that the tooling was public, and the human was barely in the loop.

Security officials at Black Hat this month confirmed that suspected Chinese operators used open-source AI agents, named as Hermes and OpenClaw, to conduct near-autonomous attacks on Taiwanese government and energy-sector targets.

Three things are new here, and only one is the attack

The tooling was public. Not a bespoke state capability, not a leaked framework — agents anyone can download. That collapses the assumption underneath most threat modelling, which is that the sophisticated adversary and the widely-available tool are different problems on different timelines.

The human was barely in the loop. "Near-autonomous" is the operative word. An operator who supervises each step is limited by attention; one who supervises a campaign is limited by nothing much. That changes the economics of intrusion far more than any single exploit does.

The targets were energy as well as government. Energy infrastructure is where an intrusion stops being an information problem.

What it does to the open-weights argument

It does not settle it, and anyone claiming otherwise is arguing from a conclusion. The honest reading is narrower: the misuse case for capable open agents is no longer hypothetical, and arguments that rested on it being hypothetical need rewriting rather than repeating.

It is worth being precise about what was demonstrated. Public agent frameworks were operationally useful to a state-aligned actor against real targets. That is not the same as saying open weights caused it, or that closed models would have prevented it.

The defensive consequence

Defences calibrated to human tempo are calibrated to the wrong thing. A campaign that probes continuously, does not tire and does not need a shift change is a different quantity from an operator at a keyboard, whatever the underlying techniques look like in a report.

See our analysis →

AI Governance Weekly — AI Governance Weekly — August 20, 2026 → · AGAT Software — AI Agent Security in 2026: What Enterprises Are Getting Wrong → · Beam — AI Agent Security in 2026: Enterprise Risks & Best Practices →