Government

Stories 5
Sources 9
Updated 2026.07.24
Researchers say Hermes AI agent was used during a suspected breach of Thailand's Ministry of Finance
Researchers say attackers targeted and likely breached multiple systems at Thailand's Ministry of Finance, then used the open-source Hermes AI agent in unattended mode to automate parts of the intrusion. Hunt.io found exposed attacker directories containing 585 files, including stolen credentials, web shells, custom scripts, and logs showing Hermes was used for privilege-escalation checks, service enumeration, filesystem traversal, and Linux post-exploitation; the ministry had not confirmed the breach at publication. — This matters because it is a real-world example of AI being used to speed up hands-on intrusion work inside a government network, which could lower the skill and time needed for follow-on attacks. Government defenders and anyone running exposed admin tools should review logs for web-shell activity, credential misuse, and suspicious enumeration, and treat exposed attacker artifacts as indicators of compromise.
Sources: Hermes AI agent used to automate attack on Thai Finance Ministry
South Korea says hackers breached National Diplomatic Academy training system and exposed diplomats’ personal data
South Korea says hackers broke into the National Diplomatic Academy’s online education system and stole personal data tied to current and former foreign ministry staff, including diplomats posted abroad. The intrusion reportedly began in April 2025 when an unknown attacker exploited a server vulnerability and remained undetected until February 2026. Exposed data includes IDs, names, email addresses, and encrypted passwords for at least 6,000 people, with some reports putting the total closer to 10,000. — This affects government personnel, including overseas diplomats, whose exposed details could now be used in targeted phishing or espionage. Affected users should treat unexpected messages cautiously and reset or review any reused credentials, while defenders should investigate the vulnerable system and related monitoring gaps.
Sources: South Korea discloses data breach impacting diplomats worldwide
Brazil investigates suspected hack of national emergency alert system after rogue warning hit phones nationwide
Brazil says an unauthorized emergency alert was sent to mobile phones across multiple states and the federal district, prompting an investigation into its public warning system. The bogus 'extreme' alert, containing the word 'misanthropy,' was reportedly issued through the Defesa Civil Alerta dispatch platform used for severe-weather and disaster warnings. SEDEC, Federal Police, and Anatel are investigating, and the platform was taken offline after the suspected intrusion. — A compromised emergency warning system can cause public panic and undermine trust in life-safety alerts people rely on during real disasters. Mobile users in Brazil should verify unusual emergency messages with official channels, while public-sector operators should review access controls, monitoring, and recovery plans for alerting infrastructure.
Sources: Brazil probes emergency warning system after nationwide rogue alert, Suspected cyberattack triggers false emergency alerts across parts of Brazil
Estonia will quarantine emails from Russian .ru domains before they reach government officials
Estonia says emails sent from Russian .ru addresses to government officials will be automatically isolated for extra screening before recipients can open them. The policy takes effect August 31 and adds .ru domains to the Estonian public sector's existing email quarantine rules for suspicious messages. Officials say the move responds to increased phishing and malware delivery from Russian servers since 2022 and is part of broader defenses against Russian hybrid threats. — This affects how Estonian public institutions handle potentially hostile communications and could reduce phishing and malware exposure for government staff. Organizations and individuals that use .ru email addresses to contact Estonian authorities may need to switch providers, and defenders should note the policy as a concrete state response to sustained Russian cyber risk.
Sources: Estonia to quarantine emails sent from Russian .ru domain before they reach government officials
Five Eyes warn China is using LinkedIn, Indeed and Upwork to recruit people with access to state secrets
MI5 and allied intelligence agencies warned that Chinese intelligence officers and their proxies are using job and networking platforms including LinkedIn, Indeed, and Upwork to spot and cultivate people with access to classified or otherwise sensitive government information. The advisory says the operators pose as recruiters, consultancies, think tanks, or research clients, rank applicants by likely access, request trial reports, then move conversations to encrypted messaging and pay through services such as PayPal, Zelle, Wise, Western Union, or cryptocurrency in exchange for non-public information. — This is a real-world espionage and social-engineering threat aimed at government, defense, foreign-affairs, academic, media, and policy workers. People in or near sensitive roles should treat unsolicited research, consulting, or recruiter outreach on these platforms as potentially hostile, report suspicious contact, and avoid sharing resumes or non-public work details casually.
Sources: Five Eyes: Watch out for odd LinkedIn connection requests, China's back on the hunt for state secrets, Five Eyes warn Chinese spies are using job sites to recruit insiders, Five Eyes: Chinese Spies Target Government, Military Staff With Fake Job Opportunities (+1 more)