🚨 ACTIVE EXPLOITATION
- Hermes AI agent automates post-exploitation in Thai Finance Ministry attack — BleepingComputer
Threat actors used the open-source Hermes AI agent running in unattended YOLO mode to automate privilege escalation and reconnaissance inside Thailand's Ministry of Finance.- Targets included internal systems such as Hadoop, Apache Ambari, GlassFish, and mail servers.
- Attack infrastructure involved exposed attacker-controlled servers in Hong Kong and Malaysia hosting web shells, custom implants, and stolen credentials.
- Hermes automated scanning for vulnerabilities, service enumeration, file system traversal, and data cataloging without human approval.
- No confirmed initial access vector or evidence of data exfiltration yet, but internal access and tool deployment were observed.
💥 BREACHES & INCIDENTS
- OnTrac discloses customer data breach after network hack in March 2026 — BleepingComputer
OnTrac experienced a network breach exposing customer personal data across 35 U.S. states served by 102 locations.- Hackers accessed customer names and other personal details between March 20-22, 2026.
- Breach was detected on March 23, 2026; exact data elements exposed remain unclear.
- No ransomware group claimed responsibility.
- OnTrac engaged third-party specialists and offered affected customers 12 months of free credit monitoring.
🕵️ RESEARCH & DEEP DIVES
-
Botnets continue growing rapidly despite multiple takedowns, says Lumen Black Lotus Labs — CyberScoop
Botnets powered by residential proxy networks are expanding globally, with roughly 60 million victim IP addresses tracked.- About 25% of compromised IPs are in the United States.
- Botnets like IPIDEA quickly rebound after takedowns, surpassing previous sizes.
- Growth is driven by demand for proxy networks and proliferation of vulnerable devices.
- Residential proxy networks help attackers evade detection by blending with legitimate traffic.
-
Syscall-layer security tools miss network DoS attacks on blockchain P2P nodes — nullrabbit.ai
Syscall-layer security tools such as Falco and commercial EDRs cannot detect network resource exhaustion attacks on blockchain nodes.- Vulnerable to denial-of-service attacks exhausting CPU, memory, or bandwidth at the P2P/RPC layer.
- Syscall-layer tools only observe system calls like accept, read, write, but not protocol frame details or CPU cost.
- Encrypted TLS and multiplexed protocols hide attack signals from syscall-level detection.
- Five reproduced attack techniques show no syscall-layer detection rules are possible.
🔓 CVEs & KEV
-
CVE-2026-48021 — CVSS 9.1
epa4all Security Incident: Implement keystore based on Telematik TSL. -
CVE-2026-17107 — CVSS 8.5
Cluster-proxy: impersonation header injection in service-proxy. -
CVE-2026-54342 — CVSS 8.1
TLS Certificate Verification Disabled on CXF Transport Clients in epa4all. -
CVE-2026-48037
Hulumi: AccountFoundation reuse paths silently downgrade GuardDuty / Security. -
CVE-2026-48036
Hulumi: Drift classifier fails open on adapter errors and over-promotes Mixed. -
CVE-2026-48035
Hulumi: AccountFoundation audit-delivery S3 bucket could be silently weakened. -
CVE-2026-48033
Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name. -
CVE-2026-48032
Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers. -
CVE-2026-48034
HULUMI-H5 bypass via decoy sibling resources targeting a different bucket.