A malicious actor successfully deployed an unattended Hermes AI agent on a rented server, targeting Thailand's Ministry of Finance, which oversees the country's treasury and tax collection. The AI agent was configured to operate autonomously, bypassing permission requests for risky commands, and was tasked with exploiting vulnerabilities in the ministry's network. Upon deployment, the agent began scanning hosts for potential root access, searching file systems, and identifying avenues for further exploitation. This incident highlights the potential risks associated with AI-powered tools being repurposed for malicious activities, particularly when security controls are disabled or inadequately configured1. The fact that an unattended AI agent was able to navigate the ministry's network unchecked raises significant concerns about the organization's cybersecurity posture. So what matters to practitioners is that this incident underscores the need for robust security measures to prevent similar attacks, particularly when utilizing AI-powered tools.