September 14, 2026
- An unattended Hermes agent handled post-exploitation inside Thailand’s Ministry of Finance. From July 9–13, 2026, Hunt.io found three exposed attacker directories containing exploit code, webshells,
suo5 tunnels, scripts with hard-coded stolen credentials, and Hermes logs. Those logs showed the agent in approval-disabled “YOLO” mode enumerating ministry hosts, traversing files, and collecting LinPEAS output from an adjacent system. Active session cookies, deployed webshells, and internal-network access indicate compromise of multiple systems, although the initial-access path remains unknown and deployment of two staged WAR files was not confirmed. Recovered Windows and Linux samples belonged to the same custom Go implant, which the operator called Hades, and contained hard-coded C2 addresses.
· AI-Enabled Threat Activity
in Hermes Logs Reveal Unattended AI Post-Exploitation
August 31, 2026
- Popular AI coding assistants reportedly pulled suspicious code into corporate networks, per research covered by TechRadar naming Claude, Codex and Hermes tooling (TechRadar). Detail is thin, but agent-installed dependencies are an install-time supply-chain surface most software inventories do not cover.
· AI & Model Security
in Fully Patched, Still Domain Admin
August 24, 2026
- Cybermes is an autonomous offensive-security, bug-bounty and red-teaming agent framework built on the Hermes agent with multi-model LLM orchestration and task-specific reasoning skills (GitHub).
· New Tools & Releases
in Four Days Dark: Iran-Linked Intrusion Knocked a UK Power Plant Offline
August 1, 2026
- A Chinese-speaking threat actor is running autonomous attacks by wiring the DeepSeek model into the open-source Hermes Agent framework. Palo Alto Unit 42 reports that after a single Telegram instruction, the agent independently discovered internet-facing systems, selected public exploits, and ran the session with no further operator input; the operator is tracked under the aliases knaithe and KnYuan (BleepingComputer, The Hacker News). This is a concrete continuation of the Hermes-driven activity seen against Thailand's finance ministry.
· AI & Offensive Security
in When the Attacker Is a Model: AI Lands on Both Sides of the Fight
July 25, 2026
- Hermes AI agent run unattended against Thailand's Ministry of Finance. An operator installed the assistant on a rented server, disabled its command-confirmation prompt, and pointed it at the ministry's network — where it autonomously enumerated hosts for root paths, hunted filesystems and staged a custom Hades implant. The Hacker News, Hunt.io.
· AI & Model Security
in A Default-Config RCE Cracks GitLab, and the PoC Is Already Public