Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

2026-07-24T14:51:47Z562ecee54508fe3a6915d5c556a13bd7e283421073fb5f920dc2a5f181f4e6dc
Adobe-AcrobatCISA-KEVCVE-2026-16232CVE-2026-48294CVE-2026-8933Chaos-ransomwareCheck-PointGemini-3.5-Flash-CyberHades implantHermes AILaundry BearRussia-linkedThailandUAC-0099UbuntuUkraineZimbrabrowser-C2cyber-espionagefake-notepad++-pluginmsaRATphishingsupply-chainvulnerability-management

What happened

This collection of reports highlights multiple high-risk active campaigns and notable vulnerability disclosures. Hunt.io detected a cyber-espionage intrusion against Thailand’s Ministry of Finance involving a Hermes AI agent for unattended reconnaissance and a staged Hades implant. CERT-UA attributes a phishing campaign to Russia-aligned UAC-0099 that delivers malware via a fake Notepad++ plugin and an evasive loader. U.S. agencies warn Laundry Bear is exploiting unpatched Zimbra servers to steal mailboxes, while CISA added several flaws (including SharePoint and Check Point issues) to its KEV

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
562ecee54508fe3a6915d5c556a13bd7e283421073fb5f920dc2a5f181f4e6dc
Enrichment time
2026-07-24T14:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.