Hunt.io and researcher Bob Diachenko reported an intrusion targeting Thailand’s Ministry of Finance in which the open-source Hermes AI agent allegedly ran unattended, conducting reconnaissance and data harvesting across compromised internal systems. The supplied snippets say Hermes executed post-exploitation tasks such as running LinPEAS, checking privileged binaries, and enumerating web roots with sensitive personnel data, while a separate Hades implant was staged on the same infrastructure. The evidence supports material automation, but does not independently establish how access was obtained, who operated the tools, or precisely how much human direction Hermes received beyond being configured to run unattended.
No intersection was found in Scott’s wikis or the radar’s accumulated pages. The incident is broadly adjacent to agentic security, but the supplied material does not connect it to a position, project, or previously tracked development of Scott’s, and the unresolved degree of autonomy limits its significance.
queries asked of Scott's wikis
- autonomous cyber agents and human-in-the-loop boundaries
- coding-agent harnesses for unattended tool execution
- agent permissions sandboxing and blast-radius controls
- AI agent audit trails and action provenance
- dual-use open-source agents and capability governance
- security implications of YOLO-mode agent autonomy
2026-07-31T16:30:04Z
Repeated triggers have produced no case-specific evidence beyond the original exposed-files account, and there is no sign that a forensic or official investigation is imminent. The episode has faded without resolving Hermes’s attribution, initial access, or degree of autonomy.
2026-07-31T15:29:10Z
The latest trigger contains no identifiable case-specific evidence and does not alter the single-source account of Hermes’s role or autonomy. Repeated engagement updates are informationally exhausted; wait for forensic disclosure, an official finding, or an independent investigation.
2026-07-31T14:27:29Z
The nominal attachment contains no identifiable case-specific evidence, leaving Hermes’s attribution, initial access, and degree of autonomy dependent on the original exposed-files report. Repeated reobservation is exhausted; defer review until an official finding, forensic disclosure, or independent investigation appears.
2026-07-31T13:25:58Z
The nominal attachment provides no identifiable case-specific evidence and does not change the original exposed-files account. Repeated broader amplification has exhausted its informational value; revisit only if forensic disclosure, an official finding, or an independent investigation appears.
2026-07-31T11:27:33Z
The trigger adds no identifiable case-specific evidence; the episode still rests on the original exposed-files account, with attribution, initial access, and Hermes’s autonomy unresolved. Repeated reobservation should not drive further review absent forensic disclosure, an official finding, or an independent investigation.
2026-07-31T09:25:04Z
No new case-specific evidence is present; the trigger reflects reobservation of already-known material rather than movement on Hermes’s attribution or autonomy. Keep the case cold and revisit only if forensic disclosure, an official finding, or an independent investigation emerges.
2026-07-31T08:24:42Z
The apparent update adds no independent, case-specific evidence about Hermes’s attribution, initial access, or operator direction; it is further amplification of broader agentic-cyber risk. Keep the episode cold until forensic disclosure, an official finding, or a genuinely independent investigation appears.
2026-07-31T07:28:29Z
The latest attachment adds no case-specific corroboration; attention remains driven by broader agentic-cyber discussion rather than evidence about Hermes’s attribution or autonomy. Pause frequent review until forensic disclosure, an official finding, or another independent investigation appears.
2026-07-31T06:24:10Z
The newly attached activity remains broader context about agent-assisted cyber operations, not independent evidence about Hermes’s attribution, initial access, or autonomy in this incident. Repeated amplification no longer merits hourly review; wait for forensic disclosure or an official finding.
2026-07-31T05:22:41Z
No new case-specific corroboration changes the assessment: the Hermes attribution, initial access, and degree of human direction still rest on the original exposed-files investigation. Broader cyber-agent activity is repetitive context rather than movement in this episode.
2026-07-31T04:22:47Z
No case-specific evidence has arrived beyond the original exposed-files report; the Anthropic discussion only reinforces the broader plausibility of agent-assisted intrusions. Hermes’s attribution, initial access, and degree of operator direction remain uncorroborated, so further engagement is repetitive amplification rather than movement.
2026-07-31T02:22:31Z
The new activity is continued amplification of broader agent-assisted cyber risk, not independent evidence about Hermes’s role, initial access, or operator direction in this incident. Keep the case open but cold pending forensic disclosure or an official investigation.
2026-07-31T01:24:47Z
Anthropic’s broader incident research shows agent-assisted cyber operations are credible, but it does not independently corroborate the Hermes attribution, initial access, or degree of human direction in this specific intrusion. The case remains dependent on the original exposed-files investigation and should stay cool pending forensic or official findings.
2026-07-30T23:21:04Z
evidence attached: hn.story.49116922 — Anthropic's investigation of real-world cybersecurity incidents materially contextualizes whether the Hermes case involved genuine agentic intrusion and how much human direction was required.
2026-07-25T17:21:42Z
The added item is a duplicate distribution link, not independent corroboration, and contributes no evidence about initial access or Hermes’s degree of autonomy. The incident remains consequential but thinly sourced, so attention should cool pending forensic or official findings.
2026-07-25T17:21:22Z
evidence attached: hn.story.49048958 — shared external link with case evidence
2026-07-24T22:24:13Z
grounded: novel/low — No intersection was found in Scott’s wikis or the radar’s accumulated pages. The incident is broadly adjacent to agentic security, but the supplied material doe
2026-07-24T22:23:41Z
origin walked (codex/luna, conf 0.98): anchor hn.story.49042205 -> echo.blog.83b1ed2dd1 by Hunt.io and Bob Diachenko
2026-07-24T22:22:44Z
case created — A named agent's alleged role in a real government intrusion is a bounded, consequential capability episode despite currently thin evidence.