← Back to feed
breaches incidentsCVSS 7.8 highCVE-2026-31431CVE-2026-43284CVE-2026-435004 sources · 3h ago

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

CVE-2026-31431 disclosed: In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associ

AffectedThailandHong Kong SAR China Apache Apache Ambari Cloudera GlassFish Hadoop HiveServer2 Linux Ministry of Finance Redhat Thailand Thailand Ministry of Finance Bob Diachenko
4 outlets · 2 origins · Balanced
United States × 3India × 1

No Reader read of this story yet.

Perspectives

The story's competing narratives, side by side — grouped by stance, with every outlet's origin and affiliation visible.

Neutral reportingNeutral reporting

Coverage focuses on a threat actor allegedly leveraging an unattended Hermes AI agent for post-exploitation automation against Thailand’s Ministry of Finance, alongside the disclosure of CVE-2026-43503 (a Linux kernel shared-frag marker bug) and other kernel/sudo/Hadoop flaws. Outlines differ on whether full system compromise occurred and emphasize log-based detection of internal scans and default-exploit usage.

The Hacker NewsBleepingComputerNVD / CVE

What to expect

First-order impacts with their likely second-order effects — direction and horizon per node.

  • Thailand Ministry of Finance post exploitation activity observed · immediate
  • Linux kernel deployments patch required · days
  • Hadoop / HiveServer2 deployments misconfiguration risk · days
  • sudo / polkit users privilege escalation risk · days

Sources (4)

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry — Prism