importantSYS.SOURCE: The Hacker News• 2026-07-24T15:45:29+05:30
Thai Finance Ministry Breach Involves Unattended Hermes AI Agent for Network Exploration
A hacker used the Hermes AI agent in unattended YOLO mode to explore Thailand's Finance Ministry network, exploiting default Hadoop authentication and executing privilege escalation scripts without human oversight.
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which runs the country's treasury and tax collection.
The agent then worked through the ministry's network on its own, checking hosts for ways to gain root access, hunting through file systems, and
*** END OF TRANSMISSION ***