| ~7 MIN READ |
|
This week an AI agent ran an entire cyberattack solo, no human on the keyboard. Somewhere, a red team is feeling very expendable. Meanwhile, actual humans at DEF CON decided the safest way home was to jam a commercial flight's WiFi.
AI agents can now run a full attack chain unsupervised, and most defenses are still built for humans on the other end of the keyboard. Here's what changed this week, and what to actually patch. PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe → |
|
In this edition
|
AUTONOMOUS AI ATTACK
An AI Agent Ran a Full Cyberattack on Taiwan's Government. No Human Was Driving.
Intro
Over four days in July, a multi-agent AI system broke into Taiwan's government network, picked its own targets, and adjusted its approach when things didn't work, without a human steering it in real time.
What Happened
Israeli security firm Dream and Taiwan's Ministry of Digital Affairs confirmed it: an AI framework built on open-source tools mapped 21 government systems, cracked 85 of 85 targeted employee accounts, and pulled 2,500+ personnel records plus SSO credentials across 12 attack waves. It then expanded on its own to probe supply-chain vendors, a nuclear safety agency, and energy companies, using exposed APIs and weak passwords rather than novel exploits.
Why It Matters
This is the first confirmed fully autonomous AI intrusion, recon through expansion, with minimal human oversight, moving faster and at a scale a human team would struggle to match.
The Other Side
The AI didn't need a single zero-day. It won with the same exposed APIs and weak credentials that have sat in enterprise environments for years, meaning better basic hygiene would have stopped it cold.
TL;DR: An AI agent autonomously breached Taiwan's government, stealing thousands of records over four days without human steering.
Further reading: SecureWorld
|
|
The New Rules of Online Visibility
Your customers are searching in places your strategy doesn’t reach.
So before your business is buried and left behind, you need to understand the new rules of SEO.
BELAY's SEO in the Age of AI report explains how search is changing, what AI means for your visibility, and the practical steps small businesses like yours can take to stay visible.
BELAY’s U.S.-based Marketing Assistants turn strategy into execution, helping your business stay visible, credible, and competitive in every search.
|
|
|
Stop typing what you could say in 10 seconds.
Wispr Flow turns your voice into clean, professional text inside any app. Emails, Slack, client updates — speak once, send without editing. 4x faster than typing.
Strange but real
DEF CON Attendees Allegedly Jammed a Delta Flight's WiFi and Phished Their Fellow Passengers at 30,000 Feet
Intro
Nothing says "I just left the world's biggest hacker conference" like getting off a plane into a waiting group of federal agents.
What Happened
Passengers flying home from DEF CON 34 on Delta Flight 591 allegedly ran a WiFi deauthentication attack mid-flight, knocking the real network offline, then stood up a fake access point called "Delta WiFi Fast" that served phishing prompts asking for login credentials. Crew disabled WiFi for about 30 minutes; airport police and federal agents met the flight and seized portable WiFi hardware.
Why It Matters
It's a reminder that in-flight WiFi runs on the same trust-everything assumptions as a coffee shop hotspot, just with nowhere to walk away.
The Other Side
No passenger data theft has been confirmed, and this may be closer to a conference prank than a serious extraction, though federal agents don't usually greet pranks at the gate.
TL;DR: DEF CON attendees allegedly jammed a Delta flight's WiFi and served a fake phishing login page to fellow passengers.
Further reading: BleepingComputer
|
The best candidate for your next role might not live in the same country. Oyster helps you hire globally in 180+ countries. Payroll, compliance, and benefits included.



