Key Findings Attacker deployed Hermes AI agent in "YOLO mode" (disabling permission checks) against Thailand's Ministry of Finance, automating reconnaissance and privilege escalation attempts Exposed staging server in Hong Kong contained 585 files, 470 MB of attack tooling, active AI agent logs, web shells, and stolen credentials with directory listing enabled Agent performed unattended reconnaissance including kernel vulnerability scanning, privilege escalation checks, and f