Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
2026-07-24T14:51:47Z•562ecee54508fe3a6915d5c556a13bd7e283421073fb5f920dc2a5f181f4e6dc
Adobe-AcrobatCISA-KEVCVE-2026-16232CVE-2026-48294CVE-2026-8933Chaos-ransomwareCheck-PointGemini-3.5-Flash-CyberHades implantHermes AILaundry BearRussia-linkedThailandUAC-0099UbuntuUkraineZimbrabrowser-C2cyber-espionagefake-notepad++-pluginmsaRATphishingsupply-chainvulnerability-management
What happened
This collection of reports highlights multiple high-risk active campaigns and notable vulnerability disclosures. Hunt.io detected a cyber-espionage intrusion against Thailand’s Ministry of Finance involving a Hermes AI agent for unattended reconnaissance and a staged Hades implant. CERT-UA attributes a phishing campaign to Russia-aligned UAC-0099 that delivers malware via a fake Notepad++ plugin and an evasive loader. U.S. agencies warn Laundry Bear is exploiting unpatched Zimbra servers to steal mailboxes, while CISA added several flaws (including SharePoint and Check Point issues) to its KEV
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 562ecee54508fe3a6915d5c556a13bd7e283421073fb5f920dc2a5f181f4e6dc
- Enrichment time
- 2026-07-24T14:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.