Introducing the AI Risk Explorer (AIRE) – a platform that monitors large-scale AI risks, including cyber offense, biological risk, loss of control, and manipulation.
We collate emerging evidence to help decision-makers assess and manage AI risks effectively.
Chinese-speaking actor used a multi-agent AI framework (Hermes+OpenClaw) to autonomously breach Taiwanese govt agencies, planning expansion to nuclear safety. Agents cracked 85 credentials, installed backdoors, and exfiltrated 2,564+ personnel records. Guardrails bypassed via a fake pentest.
North Korean threat actor Kimsuky is building local AI infrastructure using off-the-shelf tools, as reported by Genians.
The stack combines multiple local LLMs run via Ollama, GPT4All, and Msty; LocalDocs for RAG; and a growing collection of agent-development libraries (LangChain, Semantic Kernel, Microsoft.Agents).
Kimsuky (aka Velvet Chollima, Emerald Sleet, APT43) has previously been observed using Western AI for several purposes:
- ChatGPT for intelligence collection and spear phishing (Feb 2024)
- Gemini for research, reconnaissance, payload development, and scripting (Jan 2025)
- ChatGPT for intrusion research, scripting, and vulnerability investigation, alongside fellow DPRK group Stardust Chollima (Feb 2025)
- ChatGPT to generate fake South Korean military and government ID cards (Sep 2025)
Running AI locally now keeps Kimsuky's activity off Western-run services, reducing the risk of exposure. The group also seems to be expanding from using AI for social engineering and exploratory research toward integrating it across its overall attack operations, including malware development. The actor is known for its attacks against foreign diplomatic missions and militaries.
Stanford researchers used AI models Evo 1/2 to design bacteriophages targeting E. coli. 16 out of ~300 variants proved viable. This is the first time AI has designed a complete, functional viral genome from scratch.
A coordinated wave of cyberattacks targeted major Wall Street hedge funds, including Two Sigma, Citadel, and Point72. The attacks leveraged AI-driven vishing to mimic executives' voices and trick employees into granting system access. Reported by @Bloomberg.
On July 22, CISA updated an advisory warning that Iranian-affiliated actors were targeting exposed PLCs across US critical infrastructure. Four days later, 30+ Minnesota water systems were hit in a "coordinated attack." Last week, the FBI reported that at least seven states had reported similar incidents.
The attacks have not been formally attributed, although US intelligence assesses that Iran was likely responsible and independent researchers point to IRGC-linked CyberAv3ngers. In October 2024, OpenAI disclosed that the group was using ChatGPT for reconnaissance, including querying PLC credentials, generating scripts to scan for exposed industrial devices, and researching vulnerabilities.
While AI involvement in the recent incidents remains unconfirmed, the history of IRGC-affiliated actors suggests that target discovery may have been AI-assisted. However, the operation appears to rely largely on conventional TTPs, with the scale likely attributable to victims having similar third-party network arrangements.
According to @INTERPOL_HQ, 55% of cybercrime cases across Africa in 2025 involved AI in some capacity, while only 8% of intelligence analysts at African cybercrime units have advanced AI expertise. BEC, sextortion, and synthetic identity generation were among common use cases.
Attackers drained 1,082 BTC (~$70M) from ~1,200 Coldcard wallets, brute-forcing seeds weakened by a 2021 firmware integration error.
AI involvement is not confirmed, but Reddit users report Claude Code and GLM-5.2 separately found the bug with minimal guidance.
A threat actor ran DeepSeek via the Hermes Agent framework to independently enumerate targets and vulnerabilities, source exploit tools, and initiate attacks against Chinese domestic infrastructure. Despite its breadth, the campaign was largely unsuccessful. Reported by @Unit42_Intel.
Notably, this is the third similar report in two weeks. Recently, @Huntio spotted two other intrusions executed by AI agents: one into Thai and Afghan government systems, with Claude Code as the execution engine and DeepSeek as the reasoning layer (Jul 14), and another inside Thailand's Ministry of Finance by an unattended Hermes agent run (Jul 23).
Visibility into these incidents was possible because the attacker's infrastructure was exposed, partly thanks to agentic tooling leaving a findable footprint. In the latest case, the agent itself served the operator's home directory over HTTP, revealing API keys, session logs, and scripts.
Overall, the three incidents show AI attack orchestration proliferating on open models and agentic harnesses. But visibility is selection-biased: while these findings are a window into AI-conducted attacks, exposed operations are likely the least successful rather than the most representative, and the true scale and effectiveness of agentic operations remain uncertain.