🟠 High | Source: The Hacker News
A threat actor deployed the Hermes AI agent on a rented server with autonomous mode enabled, directing it to conduct post-exploitation activities against Thailand’s Ministry of Finance without human intervention. The agent independently enumerated hosts, sought privilege escalation paths, and traversed file systems across the ministry’s network. This marks a significant escalation in attacker tooling, demonstrating that AI agents can now be weaponised to conduct complex, multi-stage intrusions at scale with minimal operator involvement.
Security Architect’s Take: Review your detection coverage for AI agent tooling signatures and autonomous command execution patterns, particularly on internet-facing systems; ensure EDR and network monitoring rules are tuned to flag rapid, systematic host enumeration and privilege escalation attempts that lack human-paced timing. Consider implementing egress controls and anomaly-based alerting that can identify the high-volume, low-dwell-time behaviour characteristic of unattended AI-driven post-exploitation.
Original advisory: Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry