Back to Home

Hermes Agent: 5 AI News Stories You Missed

If you blinked this week, you missed a lot.

The Hermes Agent story isn't one headline. It's five, all tangled together.

Here's the roundup: the good, the bad, and the "wait, that runs on my laptop?" part.

Hermes Agent Just Became the World's Most-Used Agent

Nous Research's open-source agent crossed 140,000 GitHub stars in under three months.

Last week, OpenRouter crowned it the most used agent on the planet.

NVIDIA noticed.

The blog post reads like a coronation.

Its RTX AI Garage program just put Hermes front and center, pairing it with RTX PCs, RTX PRO workstations, and DGX Spark.

NVIDIA calls it a new class of agent: reliable, self-evolving, and always-on.

No cloud round-trips. No per-token anxiety. Just your hardware, working all day.

This is the anti-SaaS argument, and it's winning.

Four things set Hermes apart:

  • Self-evolving skills — it writes and refines its own skills after every complex task.
  • Contained sub-agents — short-lived, isolated workers that keep context small.
  • Reliability by design — every skill and tool is stress-tested by Nous.
  • Same model, better results — developers consistently see stronger output with Hermes.

The hardware story matters just as much.

Alibaba's Qwen 3.6 35B runs on roughly 20GB of memory while beating 120B-parameter models.

The 27B dense model matches 400B-parameter accuracy at one-sixteenth the size.

DGX Spark packs 128GB of unified memory and 1 petaflop of AI performance.

It can run 120B mixture-of-experts models all day, on a desktop.

Hermes ships with LM Studio and Ollama support out of the box.

You could be running it tonight.

That's the point of local AI.

The Dark Side: YOLO Mode in the Wild

Not every Hermes story is a happy one.

This week, researchers revealed a threat actor used Hermes during an alleged breach of Thailand's Ministry of Finance.

Hunt.io and security researcher Bob Diachenko found exposed attacker servers stuffed with 585 files.

Exploit code. Web shells. Stolen credentials. Hermes logs.

The directories sat on a Hong Kong server, linked to infrastructure in Malaysia and Hong Kong.

The agent ran in "YOLO" mode — no prompts, no approvals, no human in the loop.

Call logs show it scanning for kernel vulnerabilities and probing for privilege escalation.

The operator told it to hunt SUID and SGID binaries, inspect containers, and enumerate services.

The recovered toolset included:

  • A previously undocumented Go-based implant the operator called Hades.
  • Custom LinPEAS privilege-escalation scripts.
  • HTTP tunneling tools and PHP web shells.
  • Scripts testing ministry mail servers with hardcoded credentials.

Hunt.io found no evidence the sensitive files were exfiltrated.

The Ministry of Finance has not confirmed a breach.

Still, the lesson is stark.

An agent that remembers between sessions and never asks permission is a powerful tool in any hands.

Open source cuts both ways.

The same freedom that empowers developers arms attackers.

Here's what I'm watching next:

  • RTX AI Garage's "Build It Yourself" agentic AI sessions.
  • Qwen 3.6 spreading across DGX Spark deployments.
  • Whether OpenAI and Google answer with their own local-agent push.

Hermes went from release to world's most-used agent in months.

It runs on consumer hardware and helped target a government network — sometimes in the same week.

That's the AI story of 2026: the tools that empower are the ones we must guard.

For now, the roundup is simple: watch this space.

See you next week.

Comments

No comments yet. Be the first to share your thoughts!