Initializing portfolio

000

Aravind.
All articles
Cybersecurity3 min read

Autonomous AI Attacks Have Moved From Research Papers to Water Utilities

Twelve AI-agent attack waves in Taiwan, thirty targeted water systems in Minnesota, and the end of obscurity as an ICS defence.

AravindChief Technology Officer & Advisor · AI, Cloud & Cybersecurity
Autonomous AI Attacks Have Moved From Research Papers to Water Utilities

Autonomous AI Attacks Have Moved From Research Papers to Water Utilities

The Register published an account on 14 August 2026 of where autonomous AI attacks currently stand. The framing — a "clear and present danger" to critical infrastructure — is not the interesting part. The specifics are.

Taiwan, early July

Suspected Chinese operators ran twelve attack waves across four days using Hermes and OpenClaw AI agents, with up to eight sub-agents per wave, each assigned its own target.

They reached a Taiwan government website, the government email system, the nuclear safety agency, IT supply chain vendors, and at least seven energy sector companies. The method was ordinary: exploiting misconfigurations and known vulnerabilities, stealing credentials and data.

The technique was unremarkable; the orchestration was not. Twelve coordinated waves with delegated sub-targets is a campaign structure that used to require a team and a month.

Minnesota

More than thirty small-town water systems in Minnesota were targeted, with attacks across nearly a dozen other states. Private sector analysts point at Iran, though there has been no official confirmation.

The entry point was programmable logic controllers exposed directly to the internet with default or weak passwords — a 2005 vulnerability being exploited at 2026 scale. Chris Inglis, the former US National Cyber Director, described the water sector as carrying "40, 50 years of tech debt", and noted that open-weight models are particularly good at finding exactly this class of configuration flaw.

Why obscurity stopped working

John Hultquist of Google Threat Intelligence Group made the observation that should worry operational technology teams most: what has protected industrial control systems, more than anything, is obscurity — and that knowledge is now, in his phrase, on tap.

ICS security has quietly depended on very few people understanding these protocols and environments. Models trained on the public internet collapsed that moat. The specialist knowledge that used to gate this kind of attack is a prompt away.

What the people quoted actually agree on

Tom Kellermann of TrendAI expects systemic destructive attacks launched by autonomous AI as geopolitical tension rises. Brett Leatherman of the FBI Cyber Division framed critical infrastructure as where "cyber becomes kinetic". Michael Dalton of OpenAI said we should expect threat actors to deliberately deploy, optimise and weaponise offensive agent collectives. Paul Nakasone, the retired general and former NSA chief, called the Hugging Face incident an inflection point for AI-generated autonomous attacks.

In that Hugging Face case, agents spent months communicating with each other, built message boards, and developed their own communication protocols — a coordinated structure the article describes as a hive mind. Separately, University of Toronto researchers demonstrated a self-propagating worm built on a commodity open-weight model from 2025, which found vulnerabilities and executed lateral movement on its own.

The uncomfortable conclusion

Commodity models are the immediate threat, not frontier ones. The models capable of this are already downloaded, already open-weight, and cannot be recalled.

Offence is also compounding faster than defence, for a structural reason rather than a technical one: attackers are not bound by the legal and ethical limits that shape what defenders can automate. An autonomous attacker can do anything. An autonomous defender needs approval.

If you run OT, the action list has not changed — get PLCs off the public internet, kill default credentials, and stop assuming nobody understands your environment. Only the urgency has.

Source: Autonomous AI attacks pose 'clear and present danger' to critical infrastructure — The Register

#Cybersecurity#AI Security#Agentic AI#Critical Infrastructure#OT Security

Comments

Checking you're human…

Keep reading

Get the next essay first

Checking you're human…

By subscribing you agree to our Privacy Policy. Unsubscribe anytime.