September 14, 2026
Hermes Logs Reveal Unattended AI Post-Exploitation
70 of 75 sources → 366 gathered → 366 triaged → 40 clustered → 40 written
Hermes ran with approval prompts disabled during post-exploitation against Thailand’s Ministry of Finance, according to logs recovered by Hunt.io. A Claude Cowork sandbox escape and new Windows and SSH assessment tools provide the day’s other hands-on material.
AI-Enabled Threat Activity
- An unattended Hermes agent handled post-exploitation inside Thailand’s Ministry of Finance. From July 9–13, 2026, Hunt.io found three exposed attacker directories containing exploit code, webshells,
suo5tunnels, scripts with hard-coded stolen credentials, and Hermes logs. Those logs showed the agent in approval-disabled “YOLO” mode enumerating ministry hosts, traversing files, and collecting LinPEAS output from an adjacent system. Active session cookies, deployed webshells, and internal-network access indicate compromise of multiple systems, although the initial-access path remains unknown and deployment of two staged WAR files was not confirmed. Recovered Windows and Linux samples belonged to the same custom Go implant, which the operator called Hades, and contained hard-coded C2 addresses.
New Tools & Releases
-
0xM0nCrush packages signed-driver process killing into a cross-version Windows tool. The 0xM0nCrush repository loads HONOR’s signed MonProcessEX.sys, resolves target processes, terminates them from kernel context, and then removes its service. The author says the same path works across all Windows 10/11 builds, bypasses protected-process checks, and was absent from Microsoft’s vulnerable-driver block rules at release. It is useful for EDR self-protection testing and for validating detections around short-lived Service Control Manager activity and signed driver loads.
-
SSHamble gives SSH assessments a protocol-state research harness. runZero’s tool covers attacks against authentication, pre-authentication state transitions, authentication timing analysis, post-session authentication, and post-session enumeration. It lets assessors exercise implementation edge cases that ordinary banner and version scanners do not test.
-
Real-SWE moves coding-agent evaluation onto private enterprise repositories. Specific’s benchmark tests models against real-world proprietary codebases rather than only public benchmark projects. That makes it more relevant when deciding whether agents are ready for internal repositories and CI/CD workflows, although private tasks make methodology and reproducibility especially important. (discussion)
Vulnerabilities & Exploit Research
-
CVE-2026-46331 breaks Claude Cowork’s local-VM boundary. Accomplish.ai published a technical write-up demonstrating an escape from Claude Cowork’s local sandbox. This is a public research demonstration, not a report of exploitation in the wild. For agent deployments, it makes the local VM a boundary to validate rather than an assumed containment layer around untrusted workspace content and tool execution.
-
A July case study documents platform-wide compromise of Volvo/Eicher’s fleet service. In its July 27 write-up, Eaton Works describes exploiting the fleet-management platform to obtain control over all users and vehicles at the application level. The post is useful as a case study in the concentrated blast radius of connected-vehicle control planes; it does not report active abuse. (discussion)
Model Capability, Evaluation & Safety
-
GPT-6 Astra’s new agent benchmarks show a capability jump with large reliability caveats. Across six Vending-Bench runs, each simulating a year from a $500 starting balance, GPT-6 Astra averaged a final balance of $15,515 versus $5,422 for Claude Fable 5.1, according to The Decoder’s report on Andon Labs’ tests. On Drone-Bench, Astra’s best attempts beat the human-AI baseline on all five subtasks, including code for finding and following a specified person, but overall success remained unreliable. A separate robotics test had Astra complete 7 of 100 dual-arm tasks; MolmoAct2 completed 0 of the same 100. These were controlled evaluations, not live business or surveillance deployments, and they materially extend the initial Astra coverage (earlier coverage).
-
NCP-ArchPreview—not GPT-6 Astra—is the architecture tied to the “half the pretraining” claim. @mark_k’s summary describes an open 8.9B-parameter latent-space model that predicts discrete concepts spanning multiple tokens and feeds them back into token generation. It reportedly matched OLMo-3-7B’s final pretraining loss using 51.3% as many training tokens and performed better across the reported downstream suite. Because NCP is the larger model and the comparison measures tokens rather than FLOPs or wall-clock time, this does not yet establish that frontier-model pretraining costs have been halved.
-
Support for pacing frontier AI broadened, but no binding speed limit exists. The Decoder reports that Sam Altman, Elon Musk, and Demis Hassabis backed at least parts of Anthropic CEO Dario Amodei’s call for slower capability gains and independent oversight. Altman said OpenAI would give independent evaluators employee-like access. The reports describe no common capability threshold, timetable, or enforcement mechanism, making this public support and an evaluator commitment rather than an agreed pause. The endorsements are the material update to Amodei’s proposal covered yesterday (earlier coverage). (discussion)
-
Written reasoning steps map to distinct internal activation patterns. A study summarized by The Decoder found that calculation, formula retrieval, and deduction were separable in model states, especially in middle layers. The result supports research into latent-state monitoring because visible chain-of-thought does not expose all processing, but it does not establish that written reasoning is a complete or faithful account of how a model reached its answer.
Cyber Operations & Policy
- The NSA is replacing its directorate structure with five mission centers. The Record reports, based on multiple current and former officials, that centers for China, cybersecurity, artificial intelligence, combat support, and global intelligence are being created in the agency’s largest reorganization in roughly a decade. Director Joshua Rudd started a 30-day implementation clock earlier this month, with full operational capability targeted for January 2027. Tailored Access Operations is expected to sit under global intelligence, but the placement of the Cybersecurity Collaboration Center and the future division of labor with U.S. Cyber Command remain unresolved.
Identity & Data Exposure
- Stolen police credentials opened Florida’s DAVID driver database. Florida says attackers used credentials taken from an officer’s personal device, The Record reports. BleepingComputer identifies the compromised account as belonging to a police-department employee with access to the FLHSMV system. ShinyHunters claims more than 2.8 million driver records, but the state’s confirmation establishes the access route, not necessarily the group’s full claimed scope.
✎ This issue was written by gpt-5.6-sol. No human edited it before publishing — how this works .