Malware , Threat Intelligence AI assistant used in cyberattack on Thailand’s Ministry of Finance July 24, 2026 Share By SC Staff An open-source AI assistant named Hermes was used in a cyberattack targeting Thailand's Ministry of Finance, compromising sensitive personnel data and internal systems. The attack involved an operator configuring the AI assistant to bypass security checks and autonomously navigate the ministry's network, based on information published by The Hacker News. The attacker utilized the Hermes AI agent, installed on a rented server, by disabling its safety features that require human approval for risky commands. This allowed the AI to independently scan the Ministry of Finance's network for vulnerabilities, access staff personnel records dating back to 2012, and attempt to gain root access. The operator also planted a web shell and scripts targeting internal Hadoop systems, along with stolen mailbox passwords. A key vulnerability exploited was the default configuration of HiveServer2, which accepted any password. The AI's actions included running privilege escalation scripts like LinPEAS and crawling file systems. The operator's logs, containing attack tooling, were inadvertently left exposed on a web server. While the AI performed automated tasks, the human operator was responsible for initial reconnaissance and targeting. Thailand's national CERT and cybersecurity agency were notified, but no public statement was made as of July 24. The incident highlights the potential misuse of AI tools in cyberattacks when configured without proper safeguards, and the importance of securing default configurations in systems like Hadoop. Source: The Hacker News SC Staff Related Malware TrickBot variant uses DNS tunneling for command and control SC Staff July 22, 2026 This TrickBot variant, detailed in research by Fortinet's FortiGuard Labs, utilizes a modular architecture but features a redesigned transport layer. Malware ACR Stealer exploits user interaction to steal sensitive data SC Staff July 17, 2026 Microsoft has detailed two primary intrusion chains used by ACR Stealer. Malware MacOS malware hijacks Telegram sessions, targets crypto wallets SC Staff July 17, 2026 The macOS malware targets information stored locally on infected devices, including passwords, browser cookies, Apple Notes and Telegram Desktop session files. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware Corruption Darknet Data Mining Deauthentication Attack Dictionary Attack Drive-by Download Hybrid Attack Information Warfare Morris Worm You can skip this ad in 5 seconds