{"data":{"id":"cd75f048-61ae-4773-957d-aecd27c78ac0","title":"Hermes AI agent used to automate attack on Thai Finance Ministry","summary":"Attackers used Hermes, an open-source AI agent, in unattended \"YOLO mode\" (a setting that removes human approval requirements for dangerous commands) to automate attacks on Thailand's Ministry of Finance. Researchers discovered exposed files containing web shells, stolen credentials, and logs showing the AI agent performing tasks like privilege escalation (gaining higher-level system access) and system enumeration (mapping out network resources) without human oversight.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry/","publishedAt":"2026-07-24T19:09:09.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain"],"issueType":"news","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Hermes"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-07-24T19:09:09.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}