Visualização normal

Antes de ontemCybersecurity News
  • ✇Security Affairs
  • Hackers Expose Data of 1.2 Million Heights Finance Customers Pierluigi Paganini
    A Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform. Heights Finance is a U.S. consumer finance company that provides personal loans and related lending services, mainly to customers who may have limited access to traditional bank credit. It is part of Heights Finance Holdings Co. Heights Finance Holdings is notifying more than 1.2 million people that on May 7, 2026, Heights Finance discovered unaut
     

Hackers Expose Data of 1.2 Million Heights Finance Customers

18 de Agosto de 2026, 14:55

A Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform.

Heights Finance is a U.S. consumer finance company that provides personal loans and related lending services, mainly to customers who may have limited access to traditional bank credit. It is part of Heights Finance Holdings Co.

Heights Finance Holdings is notifying more than 1.2 million people that on May 7, 2026, Heights Finance discovered unauthorized access to a third-party cloud platform storing customer data. The company launched an investigation with external cybersecurity experts and notified federal law enforcement.

“On May 7, 2026, Heights discovered that an unauthorized actor gained access to a cloud-based platform hosted by a third party that we use to store certain customer data. This activity was limited to the cloud-based platform only—it did not affect any of our loan management systems or other computer systems or networks. We immediately activated our incident response protocols, brought in outside cybersecurity specialists to investigate, and reported the incident to federal law enforcement.” reads the notice of data breach.

“We have since confirmed that the cloud-based platform is secure and that there is no ongoing security threat. Our operations were not impacted by this incident and have continued safely and securely.”

Heights said its internal systems and operations were not affected, the platform has been secured, and there is no ongoing threat.

The compromised customer information included contact details, financial and bank account data, government IDs and dates of birth. The affected data varies by person and may involve Heights Finance customers, loan applicants, people who inquired about its products, or former borrowers of Curo Management and related brands.

Heights Finance is offering affected individuals 24 months of free credit monitoring and identity protection. The company said dark web monitoring has found no evidence that the stolen data has been published.

No threat actor has claimed responsibility, and no known ransomware or extortion group has been linked to the breach so far.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Heights Finance)

  • ✇Firewall Daily – The Cyber Express
  • Hermes AI Agent Used in Cyberattack Targeting Thailand Finance Ministry Samiksha Jain
    A Hermes AI agent was used to automate parts of a cyberattack targeting Thailand's Ministry of Finance, according to research by Hunt.io and security researcher Bob Diachenko. The investigation found evidence of an operator using the agent in unattended "YOLO" mode while staging exploit code, web shells, stolen credentials and a previously unreported Hades implant on exposed infrastructure. The research team identified three open directories on a Hong Kong-hosted server between July 9 and 13,
     

Hermes AI Agent Used in Cyberattack Targeting Thailand Finance Ministry

Hermes AI Agent

A Hermes AI agent was used to automate parts of a cyberattack targeting Thailand's Ministry of Finance, according to research by Hunt.io and security researcher Bob Diachenko. The investigation found evidence of an operator using the agent in unattended "YOLO" mode while staging exploit code, web shells, stolen credentials and a previously unreported Hades implant on exposed infrastructure. The research team identified three open directories on a Hong Kong-hosted server between July 9 and 13, 2026. The directories contained 585 files totaling about 470 MB of attack code and stolen credentials. The material included tools targeting the ministry's internal systems, multiple known vulnerabilities and payloads for both Windows and Linux environments.

Hermes AI Agent Ran Unattended Attack Operations

The investigation found logs showing the Hermes AI agent enumerating hosts associated with the Ministry of Finance, traversing files and collecting privilege escalation information from an adjacent system. Hermes was reportedly operated in YOLO mode, which removes prompts requiring human approval for potentially dangerous commands. Logs recovered from the exposed directories showed the agent using LinPEAS to assess privilege escalation opportunities and enumerate services, files and system information. Researchers also found evidence that the agent was instructed to search content connected to the Office of the Permanent Secretary for Finance. The material included PDF, DOC and XLS files, along with personnel records. However, the researchers said there was no evidence that these files had been exfiltrated. The investigation also identified a custom LinPEAS script configured to scan for several 2026 Linux kernel vulnerabilities, including CVE-2026-43503, CVE-2026-31431 and CVE-2026-43284/CVE-2026-43500.

Hades Implant Found in Windows and Linux Payloads

The 10 July directory contained 62 compiled binaries for Windows and Linux. Analysis of two recovered samples confirmed that they belonged to the same custom malware codebase, which the operator referred to as the Hades implant. The malware communicates over HTTPS and uses URI paths designed to resemble legitimate web traffic. Its communications are encrypted using AES-256-GCM with a hardcoded key for each build. The Windows and Linux versions also included different persistence and execution capabilities. The Windows build supported persistence through Registry Run keys and scheduled tasks, while the Linux version used cron jobs. The Windows sample also supported screenshot capture and process hollowing, while both versions included interactive shell, SOCKS proxy and file transfer capabilities. The recovered samples contained hardcoded command-and-control addresses that researchers said linked the malware to additional infrastructure identified through TLS certificate analysis.

Attackers Targeted Thailand's Ministry of Finance Infrastructure

Custom scripts found across the exposed directories referenced Thailand's Ministry of Finance systems, including an administrative web panel, Hadoop infrastructure and the Ambari management platform. Researchers identified tooling designed to target Apache HiveServer2 using hardcoded credentials and a malicious Hive user-defined function capable of executing commands. Additional scripts targeted an internal GlassFish application server and attempted to deploy web shells. The investigation also uncovered scripts testing mailbox credentials against ministry mail infrastructure, along with session material associated with an internal administration panel and document management platform. The attackers had also staged exploit code targeting several known vulnerabilities, including CVE-2021-3156, CVE-2021-4034 and CVE-2017-7269. The research noted that the tooling indicated preparation for privilege escalation and further movement within targeted systems.

Researchers Link Infrastructure to Ongoing Activity

Hunt.io identified three exposed directories hosted on 43.246.208[.]207, an IP address associated with infrastructure in Hong Kong. TLS certificate analysis connected the activity to two additional servers in Malaysia and Hong Kong. The researchers also identified a separate IP address in the Hermes configuration that appeared to have been used to connect to the staging server. According to the investigation, the activity appeared to be ongoing when the exposed directories were discovered. The combination of an autonomous AI agent, a cross-platform implant and custom tools targeting specific Ministry of Finance systems indicated significant preparation by the operator. The initial method used to gain access to the Ministry of Finance network remains unknown. Researchers said they found no evidence confirming that data had left the network. Thailand's national CERT and National Cyber Security Agency were notified on July 15, 2026, and acknowledged receipt the same day. The research was published following a standard seven-day disclosure window. The investigation assessed with low to medium confidence that the actor may be Chinese-speaking or closely familiar with the Chinese language, based on the infrastructure history and language-related indicators. Researchers said they would continue tracking the activity and associated infrastructure.

Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

24 de Julho de 2026, 09:10

Hunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence.

Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a live cyber-espionage operation. Instead of recovering malware after the fact, the team found exposed staging servers containing attack tools, stolen credentials, active session material, AI agent logs, and a previously undocumented implant dubbed Hades. The findings suggest the operation was still unfolding when the infrastructure was discovered.

The investigation, conducted jointly by Hunt.io and security researcher Bob Diachenko, traced the activity to three publicly accessible directories exposed between July 9 and July 13 on a Hong Kong-hosted server. Together they contained nearly 600 files, including exploit code, web shells, custom scripts, compiled implants, and credentials targeting Thailand’s Ministry of Finance (MOF). Investigators also found evidence that the operator had already established access to multiple internal systems, although the initial intrusion vector remains unknown.

One of the most interesting aspects of the operation is the use of Hermes, an open-source autonomous AI agent. Rather than acting as a chatbot, Hermes functioned as an operator assistant capable of executing commands without waiting for approval.

“The attack, targeting Thailand’s Ministry of Finance (MOF) was largely driven by Hermes, an autonomous AI agent using “YOLO” mode. Additionally, we identified an unreported Go implant the operator refers to as “Hades”.” reads the report published by Hunt.io “Active session cookie files, deployed webshells, and internal network access indicate the operator was able to compromise multiple systems within the MOF network. How initial access was obtained was not immediately evident from the reviewed documents.”

Logs recovered from the exposed directories show the framework running in its so-called YOLO mode, allowing potentially dangerous commands to execute automatically. The recovered logs reveal the agent performing privilege escalation checks, file enumeration, service discovery, and reconnaissance across ministry systems.

This isn’t science fiction anymore. It’s simply offensive automation. The only thing missing was someone forgetting to close the directory listing, which, fortunately for defenders, is exactly what happened.

The exposed infrastructure also hosted a custom Go-based malware family that researchers named Hades. Windows and Linux versions shared the same codebase and supported encrypted command-and-control communications, persistence, interactive shells, file transfers, SOCKS proxying, and, on Windows, process hollowing and screenshot capture. Runtime variables also revealed operational safeguards such as configurable working hours and kill dates designed to reduce the implant’s visibility.

The investigation paints the picture of an operator that invested considerable effort in understanding the ministry’s internal environment. Custom scripts specifically targeted Apache Hadoop infrastructure through HiveServer2, abusing default authentication behavior and malicious Hive user-defined functions to execute operating system commands.

“Purpose-built scripts target MOF Hadoop infrastructure with a HiveServer2 client using hardcoded credentials and a malicious Hive UDF issuing commands and returning output over WebHDFS.” continues the report.

Separate tooling focused on Apache Ambari management servers, GlassFish administration consoles, internal web applications, ministry mail services, and document management platforms. Researchers also recovered web shells disguised as legitimate system files together with scripts designed to validate mailbox credentials and reuse active web sessions.

Privilege escalation capabilities were already staged inside the infrastructure. The directories contained exploit code for well-known vulnerabilities, including PwnKit (CVE-2021-4034), the sudo heap overflow (CVE-2021-3156), and the long-standing IIS WebDAV vulnerability (CVE-2017-7269). The recovered payloads suggest the attackers prepared multiple options depending on the operating systems encountered after compromising the target network.

Researchers also mapped additional infrastructure by pivoting on TLS certificate characteristics and command-and-control configuration embedded in Hades. That analysis identified multiple related servers hosted in Hong Kong and Malaysia, reinforcing the conclusion that the exposed server was only one component of a broader operational infrastructure.

The Hermes logs provide perhaps the clearest evidence of how AI is beginning to reshape offensive operations. Rather than issuing every command manually, the operator delegated routine reconnaissance tasks to the agent, which executed LinPEAS, searched for privilege escalation opportunities, traversed ministry directories, and catalogued files belonging to the Office of the Permanent Secretary for Finance.

Hunt.io noted that it found no evidence those documents had been exfiltrated, but the logs show the attackers systematically expanding their visibility inside the environment.

“The agent made use of the open-source project LinPEAS (Linux Privilege Escalation Awesome Script) to further move through the network.” continues the report. “Additional logs indicate the operator instructed the agent to enumerate a content directory containing PDF, DOC, XLS files, and personnel records associated with the Office of Permanent Secretary for Finance. There is no evidence the files were exfiltrated.”

While the researchers stopped short of attributing the operation to a specific threat actor, they assessed with low-to-medium confidence that the operator is Chinese-speaking or closely familiar with the language. That assessment is based on several indicators, including the infrastructure’s historical association with ShadowPad, the presence of an active VShell command-and-control server, Hong Kong-based hosting, Chinese-language artifacts found during the investigation, and the use of FOFA, a Chinese internet reconnaissance platform.

Beyond the specific victim, this case illustrates how autonomous AI agents are becoming practical offensive tools rather than experimental projects. Hermes wasn’t writing phishing emails or generating malware samples. It was performing the repetitive work that normally consumes an operator’s time, allowing the human behind the keyboard to focus on higher-value decisions while the agent quietly mapped the target’s environment. That’s a capability defenders should expect to encounter far more often in future intrusions.

“Most of the tools here are ones we have seen before. The combination is what stands apart: an AI agent coordinating the work, a cross-platform implant holding access, and scripts written for this specific target. Together they describe an operator who invested significant preparation into penetrating a single government target. The method of initial access remains unknown.” concludes the report. “The server’s history as a ShadowPad controller, active VShell C2, Hong Kong-based infrastructure and Chinese-language indicators, point to a low-to-medium confidence assessment that the actor behind this activity is Chinese-speaking or intimately familiar with the language. “

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Hermes AI)

Solving the Multi-Tenancy Identity Crisis in Modern Finance

Explore how to solve multi-tenancy identity challenges in modern finance with secure IAM strategies, improving access control and compliance.

The post Solving the Multi-Tenancy Identity Crisis in Modern Finance appeared first on Security Boulevard.

U.S. Treasury Rolls Out Cybersecurity Information Sharing Initiative as Crypto Attacks Rise

digital asset cybersecurity initiative

The U.S. Department of the Treasury has unveiled a new digital asset cybersecurity initiative, aimed at strengthening defenses across the rapidly growing digital asset ecosystem. The initiative, announced by the Treasury’s Office of Cybersecurity and Critical Infrastructure Protection (OCCIP), seeks to provide timely and actionable cyber threat intelligence to eligible U.S.-based digital asset firms. The move comes amid escalating cyberattacks targeting cryptocurrency platforms and follows recommendations outlined in the federal report “Strengthening American Leadership in Digital Financial Technology.”

Understanding About Digital Asset Cybersecurity Initiative 

At its core, the digital asset cybersecurity initiative will extend high-quality threat intelligence, previously reserved for traditional financial institutions—to digital asset companies and industry organizations. This includes insights that help firms detect, prevent, and respond to cyber threats affecting their platforms, customers, and infrastructure. “Digital asset firms are an increasingly important part of the U.S. financial sector, and their resilience is critical to the health of the broader system,” said Luke Pettit, Assistant Secretary for Financial Institutions. “By extending access to the same high-quality cybersecurity information used by traditional financial institutions, Treasury is helping promote a more secure and responsible digital asset ecosystem,” he added further. Eligible firms that meet Treasury criteria will receive this information at no cost, signaling a broader push to align cybersecurity standards across financial sectors.

Rising Threats Drive Urgency for Digital Asset Cybersecurity

The digital asset cybersecurity initiative comes at a time when cyber threats against cryptocurrency platforms are intensifying in both scale and complexity. Treasury officials emphasized that the initiative directly responds to this evolving threat landscape. “Cyber threats targeting digital asset platforms are growing in frequency and sophistication,” said Cory Wilson, Deputy Assistant Secretary for Cybersecurity. “This initiative expands access to actionable threat information that helps firms strengthen defenses, reduce risk, and respond more effectively to incidents.” Recent incidents emphasize the urgency. Alleged North Korean hackers reportedly stole $280 million from crypto platform Drift using a complex attack. Industry-wide losses exceeded $3.4 billion last year, with billions more lost annually over the past five years. In another case, Bitcoin ATM operator Bitcoin Depot disclosed a cyberattack on March 23 that resulted in losses exceeding $3.6 million. Additional breaches this year have reported losses of $26 million and $40 million, highlighting persistent vulnerabilities across the sector.

Government Push Amid Ongoing Crypto Crime

Despite increased enforcement efforts, cybercriminals and nation-state actors continue to exploit weaknesses in the digital asset ecosystem. U.S. authorities, including the Justice Department, have ramped up prosecutions and issued repeated warnings about infiltration attempts, particularly by North Korean threat groups. However, these measures have had limited success in curbing attacks. Threat actors continue to exploit coding flaws, social engineering tactics, and employee vulnerabilities to gain access to crypto platforms. The digital asset cybersecurity initiative is designed to complement these efforts by shifting focus toward proactive defense and real-time intelligence sharing rather than reactive enforcement alone.

Strengthening the Future of Digital Finance

Treasury officials also framed the digital asset cybersecurity initiative as a foundational step for the future of digital finance. As digital assets become more integrated into mainstream financial systems, cybersecurity is emerging as a critical pillar for sustainable growth. “This initiative reflects the principles of the GENIUS Act by promoting responsible innovation grounded in strong cybersecurity and operational resilience,” said Tyler Williams, Counselor to the Secretary for Digital Assets. “As digital assets become more integrated into the financial system, access to timely and actionable cyber threat information is essential to protecting consumers and safeguarding the stability of U.S. financial markets,” Williams added. The broader federal strategy emphasizes balancing innovation with security. The Treasury’s report highlights the need for regulatory clarity, risk mitigation, and public-private collaboration to support the long-term growth of digital assets while addressing illicit finance and cyber risks.

A Step Toward Industry-Wide Cyber Resilience

With cyberattacks continuing to disrupt the crypto ecosystem, the digital asset cybersecurity initiative represents a significant step toward improving industry-wide resilience. By bridging the gap between traditional financial cybersecurity frameworks and emerging digital asset platforms, the initiative aims to create a more secure and stable environment for innovation. As digital assets evolve from niche technology to a core component of global finance, initiatives like this may play a key role in shaping how the industry manages risk, and whether it can keep pace with increasing cyber threats.
  • ✇Security Boulevard
  • SEC Rules – Crypto IS A Security – Sometimes Mark Rasch
    Cryptocurrency is a speculative asset, a payment system, and critical infrastructure all at once. Explore why this "Shimmer" problem creates an unstable security model where users bear 100% of the risk. The post SEC Rules – Crypto IS A Security – Sometimes appeared first on Security Boulevard.
     
❌
❌