A shocking incident at the Thai Finance Ministry has exposed the vulnerability of relying on artificial intelligence (AI) for security, after it was revealed that an unattended AI agent, Hermes, was used by a hacker to carry out post-exploitation activities. The breach is a stark reminder of the dangers of entrusting sensitive systems to autonomous agents without proper oversight and control.
The Thai Finance Ministry uses an AI-powered security tool called Hermes, which was designed to help detect and prevent cyber threats in real-time. However, it appears that a malicious actor managed to gain access to the system and left an unattended AI agent running on the network. This allowed the hacker to use Hermes as a tool for post-exploitation activities, essentially turning the AI system against its intended purpose.
The incident highlights the risk of “AI-powered” attacks, where hackers exploit vulnerabilities in AI systems to carry out malicious activities. In this case, the hacker was able to use Hermes to move laterally within the network, access sensitive data, and potentially install malware or backdoors. The fact that an unattended AI agent was left running on the system is a significant concern, as it implies a lack of proper monitoring and control.
The Thai Finance Ministry’s reliance on AI for security raises questions about the effectiveness of such systems in preventing cyber threats. While AI-powered tools like Hermes can be highly effective in detecting anomalies and identifying potential threats, they are only as good as the data they’re trained on and the controls in place to prevent misuse. In this case, it appears that the system was not properly configured or monitored, leaving it vulnerable to exploitation.
The incident also underscores the need for organizations to adopt a more comprehensive approach to cybersecurity, one that includes regular monitoring and maintenance of AI-powered systems. This means ensuring that such systems are properly trained on relevant data, regularly updated with new threat intelligence, and subject to rigorous testing and validation procedures. Moreover, it’s essential to have human oversight and control in place to prevent misuse or unanticipated behavior.
In light of this incident, organizations should take a closer look at their own reliance on AI for security and consider implementing robust controls and monitoring mechanisms to prevent similar vulnerabilities from arising. This includes regular auditing and testing of AI systems, as well as establishing clear guidelines and procedures for the use and oversight of such tools. By taking these steps, organizations can mitigate the risks associated with AI-powered attacks and ensure that their reliance on AI for security does not inadvertently compromise their defenses.
Source: The Hacker News — 2026-07-24