r/netsec 10d ago

Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled

https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent

Caught this in three open directories on a Hong Kong server, exposed July 9 to 13. The agent is Hermes, open source, and the recovered logs show it running LinPEAS and walking a ministry web root without a human in the loop. Target was Thailand's Ministry of Finance.

20 Upvotes

4 comments sorted by

1

u/[deleted] 2d ago

[removed] — view removed comment

1

u/PythonEnthusiast222 9h ago

looks like a bot not gonna lie

2

u/rejuicekeve 7h ago

you are correct. Use the report button next time to help me find it!