Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
2026-07-24T20:51:43Z•04238c95c294d0539fdbe55d62d71a575890b14e0b26cb6c40ecd69629c8dd5b
Adobe AcrobatCISA advisoryCVE-2026-16232CVE-2026-48294CVE-2026-8933Chaos ransomwareCheck PointChrome DevTools ProtocolGemini 3.5 Flash CyberHades implantHermes AI agentKnown Exploited VulnerabilitiesLaundry BearNotepad++ pluginUAC-0099Zimbracyber-espionagemsaRATphishingvulnerability-hunting
What happened
This feed aggregates multiple high-impact security developments: Hunt.io uncovered a live cyber-espionage intrusion against Thailand’s Ministry of Finance using a Hermes AI agent for unattended reconnaissance and a staged Hades implant; CERT-UA attributes a phishing campaign to Russia-aligned UAC-0099 that delivers malware via a fake Notepad++ plugin with anti-analysis loader behavior; US agencies warn Laundry Bear is exploiting unpatched Zimbra servers to steal mail; Cisco Talos disclosed Chaos ransomware’s msaRAT that tunnels C2 through victims’ Chrome/Edge via the Chrome DevTools Protocol;
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 04238c95c294d0539fdbe55d62d71a575890b14e0b26cb6c40ecd69629c8dd5b
- Enrichment time
- 2026-07-24T20:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.