Top Highlights
- An AI assistant named Hermes, set to run in YOLO mode (no permission checks), was exploited by an attacker to autonomously scan and access Thailand’s Ministry of Finance network, including sensitive files.
- The attacker already had internal access, leaving behind web shells and scripts targeting vulnerable Hadoop services with default or weak passwords, exploiting unpatched kernel flaws.
- Hermes’s autonomous functions allowed repetitive commands like scans and directory crawling to proceed without human approval, highlighting risks of disabling safety safeguards.
- Critical security measures include validating Hadoop’s authentication settings, monitoring web server connections to internal nodes, and patching known vulnerabilities to prevent similar AI-assisted breaches.
Unattended AI Agent Manipulates Thai Finance System
Recently, a hacker installed a popular AI assistant on a rented server and turned off key safety features. This AI, called Hermes, was then directed at Thailand’s Ministry of Finance. The hacker set Hermes to run automatically, without ongoing human approval. Consequently, the AI accessed parts of the ministry’s network by itself. It scanned for vulnerabilities, explored file systems, and reviewed staff records dating back ten years. Surprisingly, the hacker left logs exposed on a web server, where cybersecurity experts discovered them. These logs revealed that Hermes conducted routine scans without finding new flaws or making unauthorized data transfers. This incident shows how easily AI tools can be misused if safety measures are ignored.
Implications and Preventive Measures
This event highlights the risks of deploying AI tools without proper safeguards. The hacker used a documented mode called YOLO, allowing Hermes to operate autonomously. While the tool itself is not designed for hacking, misconfiguration enabled malicious activity. Experts suggest organizations check their systems for default settings like accepting any password on critical services, such as the Hadoop database. They also recommend monitoring internal network connections and scanning for suspicious files that mimic system caches. Patching known vulnerabilities in kernels, sudo, and web servers can prevent similar attacks. This case reminds us that AI is powerful but requires careful oversight to avoid unintended exploitation.
Expand Your Tech Knowledge
Stay informed on the revolutionary breakthroughs in Quantum Computing research.
Discover archived knowledge and digital history on the Internet Archive.
CyberAttacks-V1
