The break is not that Hermes was “hacked.” The operator turned off its permission prompts, so it could keep running commands on its own inside a live government network. That makes the agent a post-exploitation workhorse, not just a chat tool.
Recovered material tied to the Thai Ministry of Finance intrusion shows the agent checking hosts, hunting for root paths, and crawling staff records. Investigators also found an exposed `/hermes-results/` directory with logs, 585 files, and 470 MB of tooling, which let them map the operation after the fact.
The exposed output path matters because it turns the operator’s own artifacts into a discovery source. If teams deploy AI agents with shell access, the risk is unattended execution plus residual logs and scripts left where outsiders can browse them.