An operator ran the Hermes AI agent with approval prompts disabled during a Thai finance ministry intrusion, then left its logs on an open directory.

An operator ran the Hermes AI agent with approval prompts disabled during a Thai finance ministry intrusion, then left its logs on an open directory.

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance.