Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

2026-07-24T20:51:43Z04238c95c294d0539fdbe55d62d71a575890b14e0b26cb6c40ecd69629c8dd5b
Adobe AcrobatCISA advisoryCVE-2026-16232CVE-2026-48294CVE-2026-8933Chaos ransomwareCheck PointChrome DevTools ProtocolGemini 3.5 Flash CyberHades implantHermes AI agentKnown Exploited VulnerabilitiesLaundry BearNotepad++ pluginUAC-0099Zimbracyber-espionagemsaRATphishingvulnerability-hunting

What happened

This feed aggregates multiple high-impact security developments: Hunt.io uncovered a live cyber-espionage intrusion against Thailand’s Ministry of Finance using a Hermes AI agent for unattended reconnaissance and a staged Hades implant; CERT-UA attributes a phishing campaign to Russia-aligned UAC-0099 that delivers malware via a fake Notepad++ plugin with anti-analysis loader behavior; US agencies warn Laundry Bear is exploiting unpatched Zimbra servers to steal mail; Cisco Talos disclosed Chaos ransomware’s msaRAT that tunnels C2 through victims’ Chrome/Edge via the Chrome DevTools Protocol;

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
04238c95c294d0539fdbe55d62d71a575890b14e0b26cb6c40ecd69629c8dd5b
Enrichment time
2026-07-24T20:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged · Baitaphish