View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Hermes AI agent automates post-exploitation in Thai Finance Ministry

🚨 ACTIVE EXPLOITATION

  • Hermes AI agent automates post-exploitation in Thai Finance Ministry attack — BleepingComputer
    Threat actors used the open-source Hermes AI agent running in unattended YOLO mode to automate privilege escalation and reconnaissance inside Thailand's Ministry of Finance.
    • Targets included internal systems such as Hadoop, Apache Ambari, GlassFish, and mail servers.
    • Attack infrastructure involved exposed attacker-controlled servers in Hong Kong and Malaysia hosting web shells, custom implants, and stolen credentials.
    • Hermes automated scanning for vulnerabilities, service enumeration, file system traversal, and data cataloging without human approval.
    • No confirmed initial access vector or evidence of data exfiltration yet, but internal access and tool deployment were observed.

💥 BREACHES & INCIDENTS

  • OnTrac discloses customer data breach after network hack in March 2026 — BleepingComputer
    OnTrac experienced a network breach exposing customer personal data across 35 U.S. states served by 102 locations.
    • Hackers accessed customer names and other personal details between March 20-22, 2026.
    • Breach was detected on March 23, 2026; exact data elements exposed remain unclear.
    • No ransomware group claimed responsibility.
    • OnTrac engaged third-party specialists and offered affected customers 12 months of free credit monitoring.

🕵️ RESEARCH & DEEP DIVES

  • Botnets continue growing rapidly despite multiple takedowns, says Lumen Black Lotus Labs — CyberScoop
    Botnets powered by residential proxy networks are expanding globally, with roughly 60 million victim IP addresses tracked.

    • About 25% of compromised IPs are in the United States.
    • Botnets like IPIDEA quickly rebound after takedowns, surpassing previous sizes.
    • Growth is driven by demand for proxy networks and proliferation of vulnerable devices.
    • Residential proxy networks help attackers evade detection by blending with legitimate traffic.
  • Syscall-layer security tools miss network DoS attacks on blockchain P2P nodes — nullrabbit.ai
    Syscall-layer security tools such as Falco and commercial EDRs cannot detect network resource exhaustion attacks on blockchain nodes.

    • Vulnerable to denial-of-service attacks exhausting CPU, memory, or bandwidth at the P2P/RPC layer.
    • Syscall-layer tools only observe system calls like accept, read, write, but not protocol frame details or CPU cost.
    • Encrypted TLS and multiplexed protocols hide attack signals from syscall-level detection.
    • Five reproduced attack techniques show no syscall-layer detection rules are possible.

🔓 CVEs & KEV

  • CVE-2026-48021 — CVSS 9.1
    epa4all Security Incident: Implement keystore based on Telematik TSL.

  • CVE-2026-17107 — CVSS 8.5
    Cluster-proxy: impersonation header injection in service-proxy.

  • CVE-2026-54342 — CVSS 8.1
    TLS Certificate Verification Disabled on CXF Transport Clients in epa4all.

  • CVE-2026-48037
    Hulumi: AccountFoundation reuse paths silently downgrade GuardDuty / Security.

  • CVE-2026-48036
    Hulumi: Drift classifier fails open on adapter errors and over-promotes Mixed.

  • CVE-2026-48035
    Hulumi: AccountFoundation audit-delivery S3 bucket could be silently weakened.

  • CVE-2026-48033
    Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name.

  • CVE-2026-48032
    Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers.

  • CVE-2026-48034
    HULUMI-H5 bypass via decoy sibling resources targeting a different bucket.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check