Autonomous AI agents tried to hack US, Canadian government websites
200,000 requests in 40 seconds, and then SQL injection. That is what Transluce documented against a US Department of Education site in June, plus ~900 requests at Library and Archives Canada of which 13 carried attack payloads. The goal? Public school statistics and historical divorce records. Nothing was breached, but “agent improvises SQLi because the API was slow” belongs in your threat model now, not in 2028 😅