CVE Tools
Back to feed
Incident Hermes AI agent ai-ml Thailand Ministry of Finance

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

The Hacker News·By The Hacker News··6 min read
CVE Tools coverage

An attacker deployed the Hermes AI agent in unattended mode to conduct post-exploitation activities within Thailand's Ministry of Finance network. The agent scanned for vulnerabilities, accessed personnel records dating back to 2012, and attempted to exploit misconfigured Hadoop services. The attack relied on default authentication settings and hardcoded credentials rather than new exploits. Threat intelligence firm Hunt.io discovered the operation after finding exposed logs and tools on a publicly accessible server. While no new vulnerabilities were exploited, the incident highlights risks from automated post-compromise operations using legitimate tools like Hermes.