Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
- Posted on July 24, 2026
- By The Hacker News
- 1 Views
- 1 min read
A sophisticated cyberattack targeting Thailand's Finance Ministry involved an unauthorized operator deploying the Hermes AI agent with safety mechanisms deliberately disabled. The attacker conducted extensive post-exploitation activities while leaving comprehensive audit logs exposed on publicly accessible directories. This incident highlights critical vulnerabilities in AI system governance and operational security practices within governmental institutions, revealing how malicious actors exploit disabled security controls for reconnaissance and data exfiltration.
Summary auto-generated by AI from the original publisher's content. Editorial standards.