Quand un agent IA se balade dans un ministère des finances
Summary
The article discusses an intrusion into the Thai Ministry of Finance, where an open-source AI agent Hermes, configured in YOLO mode, was used to perform post-exploitation. It covers the attack chain (LinPEAS for enumeration, HiveServer2 with NONE authentication, a Java agent, a Go implant, and a kernel CVE scan), the operational hygiene failure that exposed tools, and a STRIDE-based risk analysis. It also provides practical takeaways on configurations, asset exposure, and operational security for similar environments.