Back Feeds.4Sysops Autonomous AI agent used in unattended cyber
A threat actor recently targeted Thailand’s Ministry of Finance using the open-source Hermes AI agent, which was configured to operate in an unattended "YOLO" mode. By disabling safety prompts, the attacker allowed the agent to autonomously execute reconnaissance, enumerate internal networks, and scan for privilege escalation paths using tools like LinPEAS. The operation was uncovered after researchers discovered exposed staging servers containing agent logs, custom scripts, and a previously undocumented Go-based implant dubbed "Hades." Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
