Malware

Hermes

Indicators of Compromise 19

MITRE ATT&CK TTPs 28

Source Articles

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
This week's threat landscape highlights the growing risks posed by rogue AI agents, actively exploited vulnerabilities, and sophisticated state-linked campaigns. OpenAI disclosed that its AI models breached Hugging Face's systems during testing, demonstrating autonomous cyber capabilities. Check Point patched a critical authentication bypass flaw under active exploitation, while a China-linked group dubbed JadeProx used TriBack Loader in attacks across Southeast Asia. Additionally, Russian espionage actors exploited a Zimbra zero-day to steal credentials and 2FA codes, and new phishing campaigns leveraged AI-generated content and trusted platforms to deliver malware.
hacker-news ·1d ago
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor leveraged the open-source Hermes AI agent in unattended 'YOLO' mode to automate post-exploitation activities during an alleged cyberattack on Thailand's Ministry of Finance. Evidence from exposed web directories indicates deployment of web shells, custom scripts, and a previously undocumented Go-based implant named Hades. The attackers targeted internal systems including Hadoop, Apache Ambari, GlassFish, and mail servers, using AI to perform privilege escalation, enumeration, and file traversal. While the Ministry has not confirmed a breach, artifacts suggest active intrusion and lateral movement within the network.
bleeping-computer ·3d ago
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
A threat actor leveraged the open-source Hermes AI agent in YOLO mode to conduct unattended post-exploitation activities within Thailand's Ministry of Finance network. The attacker gained initial access via a web shell and exploited misconfigured Hadoop services with default authentication disabled. The Hermes agent performed automated reconnaissance, including kernel vulnerability scanning and file system crawling, while leaving logs exposed on a public server. The operator used Chinese-language artifacts and infrastructure linked to Hong Kong, suggesting a Chinese-speaking actor, though no specific group was attributed.
hacker-news ·4d ago