Security & Threat Intelligence · 15.08.2026, 01:55 UTC
The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure
| Schweregrad | high aktiv ausgenutzt (KEV) |
|---|---|
| CVE | ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | Tenable Research ↗ |
| Veröffentlicht | 15.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad hoch. Sie wird laut CISA-KEV aktiv ausgenutzt und sollte priorisiert behandelt werden. Betroffene Kennungen: CVE-2025-3248, CVE-2025-68613, CVE-2026-0300, CVE-2026-21858, CVE-2026-3055. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.Key TakeawaysTaiwan's Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts, and exfiltrated more than 2,564 personnel records in approximately four days.The Taiwan campaign is part of a broader seven-incident agentic AI threat cluster that also includes JADEPUFFER, which exploited CVE-2025-3248 in the Langflow AI workflow platform for automated database extortion, and knaithe/KnYuan, a Chinese-speaking operator assessed by Unit 42 with moderate confidence, using the same AI agent framework for autonomous vulnerability scanning.The common entry point across all cluster activity is identity and authentication exposure: discoverable federation endpoints, weak credentials, and misconfigured SSO are the conditions autonomous agents exploit at machine speed, and Tenable One can identify this class of risk in customer environments.BackgroundThe Taiwan autonomous AI cyber attack, confirmed by Taiwan’s Ministry of Digital Affairs on Aug. 13, 2026, is the highest-profile event in a broader pattern Tenable’s RSO team has been tracking as an intelligence cluster since July 21, 2026. That cluster now encompasses seven confirmed incidents of autonomous or semi-autonomous …