CVE Tools

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

The Hacker NewsBy The Hacker News

IncidentHermes AI agent

Our summary

An attacker deployed the Hermes AI agent in unattended mode to conduct post-exploitation activities within Thailand's Ministry of Finance network. The agent scanned for vulnerabilities, accessed personnel records dating back to 2012, and attempted to exploit misconfigured Hadoop services. The attack relied on default authentication settings and hardcoded credentials rather than new exploits. Threat intelligence firm Hunt.io discovered the operation after finding exposed logs and tools on a publicly accessible server. While no new vulnerabilities were exploited, the incident highlights risks from automated post-compromise operations using legitimate tools like Hermes.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store