Daily Briefing
    By Krishna Goli

    Agentic AI Just Had Its Worst Week for Trust

    Taiwan's government got hacked by an AI agent, a supply-chain breach spilled credentials from Microsoft to Samsung, and two of the labs racing to build more autonomous systems spent the day consolidating and reshuffling instead.

    A glowing AI agent icon breaking through a firewall grid overlaid on a world map, symbolising autonomous cyber risk

    Taiwan's government got hacked by an AI agent, a supply-chain breach spilled credentials from Microsoft to Samsung, and two of the labs racing to build more autonomous systems spent the day consolidating instead of slowing down.

    Taiwan says an AI agent ran a hacking campaign against its government

    Taiwan's Ministry of Digital Affairs confirmed its cybersecurity units detected an "abnormal" attack on government agencies starting 20 July, and it wasn't a lone hacker with a laptop.

    • Israeli AI security firm Dream, which spotted the intrusion, called it a "first-of-a-kind breach": attackers built an autonomous hacking tool from open-source AI agents that behaved like a coordinated cyber team, the Guardian reports.
    • The tool compromised at least 85 government accounts, extracted more than 2,500 personnel records, then expanded to Taiwan's nuclear safety agency and seven energy companies.
    • The Financial Times, cited by the Guardian, reported suspected China-linked hackers based on Simplified Chinese in internal communications; Taiwan's ministry didn't name an attacker.

    Why it matters: a security researcher quoted in the piece cautioned there's still "a human in there somewhere" directing the agent — this isn't fully autonomous hacking yet, but the gap between "AI-assisted" and "AI-run" attacks just got a lot narrower.

    A 40-minute supply-chain breach exposed credentials across 2,500+ companies

    An attack on LiteLLM, an open-source tool widely used to route AI workloads, leaked terabytes of credentials belonging to some of the world's biggest companies.

    • Security firms CloudSEK and Hudson Rock found cloud keys, SSH keys, and AI provider tokens tied to Microsoft, Amazon, Cisco, Samsung and Salesforce, Ars Technica reports.
    • The exposure happened during a single 40-minute window in March; roughly 434,000 CI/CD pipelines had credentials exposed.
    • The group TeamPCP, described as largely teenagers, claimed credit; the campaign started with an earlier compromise of the Trivy vulnerability scanner.

    Why it matters: researcher Kevin Beaumont found one affected company's "rotated" credentials still worked when he tested them — the disclosure is landing faster than most enterprise DevOps teams can respond.

    Anthropic is reportedly in talks to buy Decart for $6 billion

    Bloomberg reports Anthropic is negotiating to acquire AI startup Decart, via CNBC-TV18, citing people familiar with the matter; the deal isn't finalised.

    • Decart helps developers squeeze more performance out of a wide range of chips and builds generative-video "world models" that can modify live video feeds instantly.

    Why it matters: this is an efficiency-and-multimodal deal, the kind labs make when bracing for margin pressure, not just a capability race.

    Google DeepMind's reshuffle traces back to Sergey Brin

    Reuters' exclusive reporting fills in what drove Google's 5 August leadership shake-up at DeepMind.

    • Brin personally pushed DeepMind staff to move faster in an April town hall, Reuters reports, after Anthropic's Claude Mythos preview raced ahead of Gemini.
    • Google delayed its new flagship Gemini model by two months after internal testing showed it still lagging rivals on coding.
    • Demis Hassabis stepped aside as DeepMind chief in favour of deputy Koray Kavukcuoglu; Gemini's two original technical co-leads quit to start their own company.

    Why it matters: Alphabet just chose commercial speed over Hassabis's broader research remit — a trade-off every lab under competitive pressure is quietly making.

    The Hexalink view

    Two threads run through today's news, and they're in tension. Agentic AI is doing exactly what labs promised — acting with less oversight, moving faster than a human team could — and that's precisely why Taiwan and the LiteLLM breach both happened. Meanwhile, the labs building these systems are optimising for competitive position, not for closing the gap between capability and control.

    If you're deploying agentic tools inside your organisation, treat this week as the baseline, not the exception. Audit what your AI agents can actually touch — credentials, APIs, live systems — before you audit what they're supposed to do. And if a vendor's pitch is "autonomous," ask who's accountable when it acts outside the brief; Australia's regulators are already answering that question for deployers, and your jurisdiction will too.

    We'll be back tomorrow with the next briefing — or catch the five-minute audio version on The AI Storm Daily podcast.