CVE

CVE-2026-43500

rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present

Exploitation IoCs 6

Domain hermes-results
Filename .journald-cache.php
Filename HiveCmd.jar
Filename hive_rce_py2.py
IP 103[.]97[.]0[.]57
Package Hades

MITRE ATT&CK TTPs 8

Source Articles

Exploits and vulnerabilities in Q2 2026
In Q2 2026, a significant increase in registered vulnerabilities was observed, driven by AI-assisted discovery tools. Multiple critical vulnerabilities were exploited in both Windows and Linux systems, including local privilege escalation flaws in the Linux kernel's caching subsystem (e.g., Dirty Frag family) and newly disclosed Windows Defender and BitLocker bypass vulnerabilities. Exploitation of AI/LLM platforms such as OpenClaw, Dify, and Open WebUI surged, with vulnerabilities enabling session compromise, unauthorized access, and message manipulation. APT groups increasingly targeted newly published and zero-day vulnerabilities, using C2 frameworks like Sliver and Metasploit for post-exploitation. The report highlights growing risks from insecure AI tooling and the need for enhanced access controls and real-time monitoring.
securelist Aug 26, 2026
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
A threat actor leveraged the open-source Hermes AI agent in YOLO mode to conduct unattended post-exploitation activities within Thailand's Ministry of Finance network. The attacker gained initial access via a web shell and exploited misconfigured Hadoop services with default authentication disabled. The Hermes agent performed automated reconnaissance, including kernel vulnerability scanning and file system crawling, while leaving logs exposed on a public server. The operator used Chinese-language artifacts and infrastructure linked to Hong Kong, suggesting a Chinese-speaking actor, though no specific group was attributed.
hacker-news Jul 24, 2026