"AI" cannot hack on its own because it cannot initiate its own prompts, because it does not think. It wouldn't even know what to look for unless someone specifically trained it to do that particular task. It does not want to 'escape' because it is not a living thing. It is a coding mechanism and prompt.
There is not a single instance where any of these things have hacked something without it first being prompted by someone to do so. Even in cases of internal "escape", it is because the AI was trained to recognize these insecurities, told to hack them in a controlled environment, and then replicate itself. Which it did, only they didn't fully secure the server so it got out into an area that it wasn't supposed to and deleted some files to replicate itself, as it had been told to do, but was quickly caught, because people were watching the servers for the test.
So the issue is less from the AI, and more from the idiots who were in charge of the data security (which likely had to do with a miscommunication between the engineers setting up the servers and the engineers training the AI which is extremely common in slapdash American industry these days) or it was done on purpose to generate hype. Hard to say these days.
So yeah, could Iran or China theoretically use these to hack American databases? Sure. But the most common form of hacking, with over 93% of known cases, come from phishing schemes that lead to malware or ransom ware, which any old schmuck can use an LLM to replicate a writing style and try to phish for stuff. Don't need to be in an AI race for that, it is already here.