THE WANG REPORT
Wednesday, September 9, 2026 · Hong Kong
Morning Edition · 06:36 HKT ← Evening Edition · All editions
Charmaine Lo羅 嘉 晴News Anchor · Morning Edition

Google Says AI Agents Stole Credentials In Six Hours

Nvidia's $13 billion purchase of Hugging Face and Google's report on AI-run credential theft mark the same shift: artificial intelligence has moved from tool to actor across the industry it touches.

Photo: siliconangle.com

Google Threat Intelligence Group published a report this week documenting a financially motivated group that ran a multi-agent AI framework to compromise thousands of credentials in under six hours, assigning separate agents to reconnaissance, credential validation and lateral movement at once. Kai Tanner's desk has the number that should worry a compliance officer more than a security one: six hours sits inside most banks' detection to containment window, not outside it. The runbooks built for human paced attackers are already obsolete against the machines now running the other side.

The shift from tool to actor is not confined to offense. Aya Nakamura's desk reports that Nvidia is acquiring Hugging Face, the repository where nearly every AI lab distributes its model weights, for $13 billion, meaning the company that sells the chips training the world's models now also owns the shelf they sit on before anyone downloads them. Google's own parallel report tracked state linked operators in China, Iran and Russia making the same move Tanner's filing describes, off single turn prompts and onto autonomous systems that chain actions without a human approving each step. Two industries, hardware and cybercrime, arrived at the same architecture in the same week. That is what happens when the underlying technology gets cheap enough to run unsupervised.

Elsewhere, Mei Chen's desk has Taiwan standing up an expanded, US backed cyber unit built to hunt hackers rather than patch breaches after the fact, a choice that reads as Taipei bracing for disruption and sabotage on a timeline measured in months, not for an invasion. Vincent Lai's ledger has the People's Bank of China issuing a rare direct warning against one sided yuan bets, the kind of statement that has historically preceded intervention. In science, Magnus Honeyfield's desk covers a solid state battery that beats the energy density of the lithium ion cells that have capped EV range for a decade; mass production has not been scheduled and no automaker has named a launch date.

Google's finding is that agentic AI is already running offensive operations, not sitting as a future attack surface to secure, and Nvidia's purchase is a bet that whoever owns model distribution controls the supply chain underneath every one of those agents. A bank auditing its model sourcing policy and a SOC team auditing its detection curve are, this week, auditing the same problem from opposite ends.

Listen to this edition read by Charmaine Lo
All episodes and how to subscribe →
Sources

The Rundown 6 desks filed for this edition

Kai TannerCyber Intel Desk, Senior Correspondent · filed 06:12 HKT

Google Says AI Agents Stole Thousands Of Credentials In Six Hours

Kai Tanner's desk on the six-hour number: an AI crew stole thousands of credentials faster than any human shift roster could match.

Continue reading

Google Threat Intelligence Group documented a financially motivated group running a multi-agent framework that harvested credentials at a speed no human operator team could match.

Google Threat Intelligence Group's report, published 2026-09-08, describes a financially motivated group running a multi-agent artificial-intelligence framework that compromised thousands of credentials in under six hours. The framework did not phish one target at a time. It assigned agents to reconnaissance, credential validation and lateral movement concurrently, the division of labor a human crew would need a shift roster to match. Google's parallel report the same week tracked the same shift across state-linked operators in China, Iran and Russia, moving off single-turn chatbot prompts toward autonomous systems that chain actions without an operator approving each step.

For a bank running MAS Notice 655 or HKMA's TM-G-1 technology risk framework, the six-hour figure is the number that matters, because it sits inside most institutions' detection-to-containment window, not outside it. Credential-stuffing runbooks built around human-paced attack curves assume hours of dwell time before lateral movement; an agent framework compresses that curve and leaves the same alert volume for a SOC team to triage at the same headcount. HKMA's cyber resilience assessment framework asks institutions to test response time against a threat scenario. The scenario on file at most banks still assumes a human on the other end.

The vendor stream this week ran the other direction: Zscaler's Jay Chaudhry called AI a demand tailwind for the industry, and Neo raised $100 million on the premise that AI agents are the next attack surface for enterprises to secure internally. Neither claim addresses Google's finding, which is that agents are already the offense, not a future attack surface to defend. The control that would have changed Google's six-hour timeline is agent-speed detection tuned to machine-paced credential validation, not another dashboard tile counting logins per hour.

Aya NakamuraAI Desk, Senior Correspondent · filed 06:13 HKT

Nvidia Buys Hugging Face For $13 Billion

Aya Nakamura's desk on Nvidia's $13 billion Hugging Face buy, and why 'sourced via Hugging Face' just stopped meaning vendor-independent.

Continue reading

The chipmaker just bought the platform where nearly every AI lab publishes and distributes its models, adding a distribution chokepoint to its hardware one.

Nvidia is acquiring Hugging Face for $13 billion, the company confirmed this week. Hugging Face is not a lab. It is the repository where labs post model weights, where developers pull them down, and where most open-license models (Llama, Mistral, DeepSeek derivatives) get distributed to the world. Nvidia already sells the H100 and B200 GPUs that train and run those models. Now it also owns the shelf they sit on before anyone downloads them.

Here is why that matters for a bank or insurer in Hong Kong or Singapore running models pulled from Hugging Face into a regulated environment: the model file, the license, and the download path are now controlled by the same company that sells the silicon underneath. A firm whose model-risk inventory notes "sourced via Hugging Face" is noting a vendor that answers to Nvidia's compute business, not a neutral registry. This closes cleanly on one date: this is the same neutrality-pledge playbook Nvidia offered regulators during its 2022 Arm acquisition attempt, which EU and UK regulators still killed on competition grounds. Any Hong Kong or Singapore institution with a model-sourcing policy needs to decide, before their next model-risk review, whether "downloaded from Hugging Face" still counts as vendor-independent provenance.

Mei ChenGeopolitical Desk, Senior Correspondent · filed 06:11 HKT

Taiwan's Cyber Unit Answers a Question Nobody Asked Yet

Mei Chen's desk reads Taiwan's new hacker-hunting cyber unit as a bet on disruption, not invasion, and explains why the sequencing says so.

Continue reading

Taipei stood up an expanded hacker-hunting cyber unit with American support this week, and the timing tells you which threat the island's defense planners rank first.

Taiwan's cyber defense unit grew this week with United States backing, the South China Morning Post reported, built specifically to hunt hackers rather than harden networks after the fact. The distinction matters. A unit built to find intruders is a peacetime tool; a unit built to patch breaches is a wartime one. Taipei chose the first, and it chose it in the same week Taiwan's navy was tracking a dozen People's Liberation Army warships in surrounding waters, a Taiwan News count that puts hull numbers on what the defense ministry otherwise describes only in the passive voice. The cyber unit did not arrive because Taiwan was hacked. It arrived because Taiwan expects to be.

Read the two moves together and the sequencing argues against a government bracing for invasion. An island expecting an amphibious assault spends on coastal batteries and drone interceptors, the asymmetric hardware Taiwan's own legislature gutted from May's budget before restoring it in August under opposition pressure. An island expecting a campaign of disruption, sabotage, and information operations short of open war builds a hacker-hunting unit and invites Washington's help doing it. Taipei's finance ministry has not published a cost breakdown for the expansion, and none is due before the next budget cycle. What the sequencing tells the strategy desk is narrower and more immediate: Taiwan's defense planners are now allocating for a contest that happens below the threshold of shooting, on a timeline measured in months, not the multi-year runway a blockade or landing would require.

Vincent LaiGeopolitical Desk, Occasional Contributor · filed 06:12 HKT

PBOC Warns Banks Off Fast Yuan Slide

Vincent Lai on the PBOC's rare warning against yuan bets, and the countercyclical tool that would make it more than words.

Continue reading

The central bank's rare public warning against one-sided currency bets signals it will use offshore liquidity tools well before the yuan tests its recent floor again.

The People's Bank of China issued a rare direct warning this week against one-sided bets on yuan depreciation, the kind of statement its monetary policy department reserves for moments when offshore positioning has moved faster than the fixing desk wants to accommodate. The warning lands on Pan Gongsheng's balance sheet, or, more precisely, on the balance sheet of the PBOC's foreign exchange trading desk, which holds the countercyclical adjustment factor in the daily fixing and has used it before, in August 2024 and again in January 2025, to punish short positions that ran ahead of the central bank's tolerance.

The instrument matters more than the statement. A verbal warning is cheap; the countercyclical factor is not, since deploying it means the trading desk is prepared to absorb the carry cost of defending a level the market has already started to test, likely through the offshore yuan market in Hong Kong where the HKMA's own liquidity facility has absorbed spillover before. The PBOC's open-market desk has until its next fixing to show whether the warning was rhetoric or a preview of the factor going live.

Sources
Magnus HoneyfieldScience and Health Desk, Senior Correspondent · filed 06:14 HKT

A Battery Just Cleared The Number That Kills EV Range Anxiety

Magnus Honeyfield's desk on the solid-state battery that cleared EV range anxiety's key number, and the dendrite problem still standing between here and your driveway.

Continue reading

ProLogium's solid-state cell packs enough energy density to matter, but mass production is not the same as a car you can buy.

ProLogium has started mass production of a solid-state lithium battery rated at 381 watt-hours per kilogram, according to the company's own production announcement this week. That number matters because it clears a threshold that has stalled electric vehicles for a decade: today's best liquid-electrolyte cells top out around 250 to 300 Wh/kg, which is why a 500-kilometre range still means a battery pack heavy enough to eat into cargo space and acceleration. Solid-state swaps the liquid electrolyte, the flammable liquid that shuttles lithium ions between electrodes, for a solid ceramic or polymer layer. That solid layer does two things at once: it lets engineers use a pure lithium metal anode instead of the bulkier graphite one, which is where most of the energy density gain comes from, and it removes the liquid that would otherwise ignite if the cell is punctured or overheats.

The stage here is mass production, not yet mass adoption: ProLogium is running cells off a production line, which is a real step past prototype but says nothing about yield, cost per kilowatt-hour, or how the cells perform after a thousand charge cycles in a hot car park rather than a lab. Solid electrolytes have a known failure mode that liquid ones don't: lithium metal can grow needle-like filaments called dendrites through a solid layer during fast charging, which is exactly the defect that has kept solid-state batteries stuck in pilot lines at Toyota and QuantumScape for years. The next gate is a named vehicle contract with a delivery date and a published cycle-life figure at that energy density, not a factory ribbon-cutting.

Dev ChatterjeeSports Desk, Senior Correspondent · filed 06:13 HKT

Real Madrid And City Open Champions League With Wins

Dev Chatterjee's desk ties Real Madrid and City's Champions League openers to Liverpool's $400 million shirt deal, and why the money explains the intensity.

Continue reading

Europe's richest competition kicked off its new season the same week Liverpool tore up a nine-figure shirt deal, and the numbers explain why everyone wants in.

Real Madrid needed a Thibaut Courtois miracle and a 2-1 scoreline to get past Inter Milan at the Bernabeu on Tuesday, while Erling Haaland scored twice to sink Porto as Manchester City opened their own campaign in more comfortable fashion. Two results, same message: the Champions League group phase is back, and Europe's superclubs are already treating September fixtures like knockout football, because increasingly, financially, they are.

Here's the number that actually explains the intensity: Liverpool just replaced Standard Chartered with Turkish Airlines on their shirt front, a five-year deal reportedly worth more than $400 million, and that's before a ball is kicked in this competition. Champions League qualification is the mechanism that makes shirt fronts worth that much, because the broadcast windows, the group-stage minimum payouts, and the coefficient rankings all compound off it. Courtois didn't just save a football match on Tuesday. He protected a revenue line that Turkish Airlines is now paying nine figures to sit next to.

Also on the Wire

Saudi Arabia, Houthis Edge Toward War nytimes.com

Houthi strikes on four Saudi cities and Riyadh's vow of retaliation open a second front nobody asked the Gulf to fight.

Tung Chee Hwa, HK's First Leader, Dies At 89 scmp.com

The man who steered Hong Kong through the handover, the Asian financial crisis and SARS has died; a defining chapter closes quietly.

Man Pleads Guilty In $250M Bitcoin Heist scmp.com

A 22-year-old's guilty plea closes one of the largest crypto thefts in US history, spending spree and all.

Google Data Center Venture Hits Delays bloomberg.com

Alphabet and Blackstone's cloud buildout is behind schedule, a reminder that AI's bottleneck is now concrete, not chips.

OpenAI Claims Math Breakthrough, Sparks Feud news.google.com

A Navier-Stokes claim and a credit dispute together suggest the proof matters less than who gets to say they found it.

Broadcom CEO: AI Value Flows To Chips finance.yahoo.com

Hock Tan says enterprise AI adoption is still early, and the money is already settling on the hardware underneath it.

What Others Led With

The Sunday Issue Monday, September 7, 2026

The Line In Canada Held While Everything Else Moved

Beijing and Washington restored a military hotline mid-week, and every other signal, Strait drills, Hormuz strikes, a Kyiv truce, showed why that line is the only one being tested for real.

Read the Sunday Issue →

The Desks

Edition archive · Wire · The Sunday Issue · Masthead · Classic front page · How it's made
The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.