Return to Threats

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

thehackernews.com 2026-07-24 AI agent abuse Critical

What Happened

Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which runs the country's treasury and tax collection. The agent then worked through the ministry's network on its own, checking hosts for ways to gain root access, hunting through file systems, and

Why It Matters

Report facts: An operator deployed the open-source Hermes AI agent on a rented server, disabled its safety prompts (YOLO/unattended mode), and aimed it at Thailand’s Ministry of Finance network, where it autonomously enumerated hosts, scanned for privilege-escalation paths, probed Hadoop/HiveServer2 defaults, and traversed file systems during post-exploitation activities.[2][3][4][6][7] The attack leveraged Hermes to automate repetitive intrusion tasks without human confirmation for risky commands, contributed to compromise of internal systems and personnel data, and was paired with web shells, credential theft, and persistence tooling.[4][6][8] RealGround analysis: This incident exemplifies AI agent abuse, where configurable autonomy and disabled safety checks turn a legitimate agent into a scalable post-exploitation platform. Organizations should harden AI agent configurations (no YOLO modes in production, strict command-approval policies), implement network-level detections for autonomous scanning and privilege-escalation tooling, and continuously red-team AI-assisted attack paths. RealGround’s Secure AI Agent Build and AI Agent Business Logic Audit can help design agents th

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI agent abuse. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html

Talk to AI CISO