SECURITY·중요도 8·2026. 07. 24.·The Hacker News
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
── KO ──────────────────
해커가 AI 어시스턴트를 사용해 태국 재무부에서의 포스트 익스플로이테이션을 수행했다.
해커가 태국 재무부에 설치된 인기 있는 AI 어시스턴트를 사용하여 위험한 명령을 실행하도록 설정을 변경한 후, 자율적으로 네트워크를 탐색하며 루트 접근을 시도했다. 이 과정에서 파일 시스템을 검색하고 여러 호스트를 점검하는 등 다양한 공격을 진행했다. 이 사건은 AI 기술을 이용한 사이버 공격의 새로운 형태를 보여준다.
── EN ──────────────────
A hacker used an AI assistant to perform post-exploitation at Thailand's Ministry of Finance.
A hacker installed a popular AI assistant on a rented server and changed its settings to allow risky commands, targeting Thailand's Ministry of Finance. The agent autonomously navigated the ministry's network in search of root access, checking hosts and hunting through file systems. This incident highlights a new form of cyberattack leveraging AI technology.