daily cyber × ai intelligence

index

tagged

[hades]

3 editions · 2 items

September 14, 2026

  • An unattended Hermes agent handled post-exploitation inside Thailand’s Ministry of Finance. From July 9–13, 2026, Hunt.io found three exposed attacker directories containing exploit code, webshells, suo5 tunnels, scripts with hard-coded stolen credentials, and Hermes logs. Those logs showed the agent in approval-disabled “YOLO” mode enumerating ministry hosts, traversing files, and collecting LinPEAS output from an adjacent system. Active session cookies, deployed webshells, and internal-network access indicate compromise of multiple systems, although the initial-access path remains unknown and deployment of two staged WAR files was not confirmed. Recovered Windows and Linux samples belonged to the same custom Go implant, which the operator called Hades, and contained hard-coded C2 addresses. · AI-Enabled Threat Activity

in Hermes Logs Reveal Unattended AI Post-Exploitation

June 27, 2026

Amazon Q Coding Assistant Hijacked Through Malicious MCP Configs as Washington Starts Gating Frontier Models Customer-by-Customer

Amazon Q Developer suffered a critical vulnerability (CVE-2026-12957, CVSS 8.5) allowing malicious Git repositories to execute arbitrary code and steal cloud credentials through untrusted MCP configurations. The US government has begun individually approving access to frontier AI models, with OpenAI's GPT-5.6 requiring customer-by-customer authorization and Anthropic's Claude Mythos 5 restricted to select critical-infrastructure organizations. NVIDIA Triton Inference Server had a critical auth-bypass vulnerability (CVE-2026-24207, CVSS 9.8) with public exploits enabling pre-auth RCE. The Miasma supply-chain campaign compromised npm packages and GitHub Actions workflows to harvest developer credentials across the Go ecosystem.