A threat actor deployed the open-source Hermes AI agent in unattended mode to automate post-exploitation activities during an alleged breach of Thailand's Ministry of Finance.
The Hermes AI agent, configured in "YOLO" (you only live once) mode, was used to execute automated attacks without human intervention following initial access to the government entity.
YOLO mode allows AI agents to operate autonomously with minimal oversight, making the tool particularly effective for scaling attack operations across compromised systems. The unattended deployment enabled the threat actor to conduct post-exploitation activities such as lateral movement, data exfiltration, or persistence mechanisms at machine speed.
Hermes is an open-source AI framework designed for agentic tasks, but its autonomous capabilities create security risks when repurposed for malicious intent. The incident highlights how legitimate AI development tools can be weaponized for government-level cyber attacks.
Thailand's Ministry of Finance has not yet released an official statement regarding the breach scope or compromised data. Security researchers are analyzing the attack to understand how the AI agent was integrated into the exploitation chain and what defensive measures could detect similar autonomous attacks.
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin exposes WordPress sites to remote code execution and complete takeover by unauthenticated attackers.
An identity theft search site claimed to possess over 150 million driver's license photos stolen from a major ID verification service. The crime site has since been shut down.
Iran-linked hackers have compromised approximately 100 American water utilities in a sustained campaign targeting critical infrastructure. The EPA is allocating $11 million in funding to strengthen cybersecurity defenses across water systems.
Attackers exploited BGP routing vulnerabilities to redirect Virtualizor VPS management software update requests to malicious servers. The compromise affected users attempting to download legitimate updates for the widely-used hosting control panel.