Skip to content

Hermes Codex — Cyber Risk Intelligence

CYBER RISK INTELLIGENCE

Know what changed.
Know what matters.
Know what to do.

Hermes continuously tracks how cyber risk evolves across vulnerabilities, software and AI systems — then turns that intelligence into actionable decisions.

🔒 100% In-Browser Privacy • Zero Server Uploads • Empirical Brier Calibration (0.1043) • OASIS STIX 2.1 / TAXII 2.1
OBSERVE

What changed today?

Hermes continuously monitors real-world shifts across the global threat landscape over the last 24 hours.

CRITICAL ACCELERATION Apache ActiveMQ Artemis

CVE-2026-67593

Public automated exploit framework published demonstrating remote unauthenticated queue wiping over Openwire port 61616.

Why it matters: Pre-auth boundary rupture allowing silent state destruction.
Who is affected: Distributed message queues exposed on WAN or cross-VPC.
ACTIVE BOTNET CAMPAIGN Spug Deployment Console

CVE-2026-90770

Automated botnet propagation abusing ping_check command concatenation on internet-facing management panels.

Why it matters: Full remote takeover of infrastructure deployment workers.
Who is affected: Spug web panels exposed without VPN boundary.
AGENTIC TOOL HIJACK MCP Filesystem Bridge

CVE-2026-AGENT-MCP

Autonomous tool execution hijacked via indirect prompt injection in ingested PDFs, triggering out-of-band data exfiltration.

Why it matters: Unmonitored pathway from untrusted model inputs to OS filesystem.
Who is affected: Autonomous LLM agents with read/write MCP bridges.
30-SECOND GUIDED TOUR

See Hermes in Action: From Signal to Decision

SIMULATED ENVIRONMENT Acme Corp (Demo Data)
147 software components
23 exposed vulnerabilities
4 KEV active exploitations
7 accelerating risks
3 critical dependencies
STEP 1 — SIGNAL & DETECTION

CISA KEV Addition & Threat Shift on n8n & MCP

2 hours ago

Hermes observed weaponized public exploit availability and CISA KEV listing for CVE-2026-85168 (n8n Git Node RCE) and CVE-2026-87911 (postgres-mcp-server).

EPSS Velocity +184% (0.18 → 0.52)
CISA KEV Status ACTIVE EXPLOITATION
Acme Corp Exposure 2 instances exposées
STEP 2 — TRAJECTORY & BLAST RADIUS

Critical Risk Acceleration: HTS Score 96/100

State transition

The affected n8n instance at Acme Corp holds direct MCP tool bindings into production PostgreSQL databases. The flaw allows lateral movement from CI/CD runners to core database records.

Hermes Threat Score 96 / 100 (CRITIQUE)
Trajectory State ↑ ACCÉLÉRATION CRITIQUE
Blast Radius Tier 1 Cloud Data Layer
STEP 3 — FALSIFIABLE FORECAST

Automated Scanning Probability within 48h: 94%

Calibrated (Brier 0.1043)

Based on Hermes calibrated forecast models across 89 historical trajectory cases, the probability of automated mass scanning against internet-exposed n8n instances exceeds 94% within 48 hours.

Forecast Horizon 48 Heures (T+2)
Confidence Factor 91% (High Confidence)
Historical Brier Calibration 0.1043 (+58% vs hasard)
STEP 4 — DECISION DIRECTIVE

Prescriptive Action Plan Generated

T0/T1 Actions

The Hermes Decision Engine prescribes immediate containment playbooks prior to enterprise perimeter rupture:

T0 (0-2h) Network isolate the n8n runner container and restrict untrusted webhook ingress ports.
T1 (2-12h) Deploy security patch n8n v2.36.2 and postgres-mcp-server v1.1.7.
T2 (12-24h) Rotate database service-role secrets and revoke persistent OAuth session tokens.
UNIFIED ENGINE

From signal to decision

Hermes is not a fragmented collection of tools, but a single continuous 7-stage intelligence lifecycle.

01

OBSERVE

What changed?

Continuous multi-source telemetry across NVD, KEV, EPSS, and weak signals.

Today's Intel →
02

UNDERSTAND

Why does it matter?

Knowledge Graph of 556+ entities and structural vulnerability chromosomes.

Knowledge Graph →
03

TRACK

How does risk evolve?

Continuous risk curves R(t), velocity, and inflection point detection.

Risk Trajectories →
04

PREDICT

What happens next?

Falsifiable probabilistic forecasts calibrated via audited Brier score.

Forecast Record →
05

DECIDE

What should we do?

Prescriptive remediation directives T0/T1 with residual risk deltas.

Decision Engine →
06

VERIFY

What happened?

Forensic failure autopsies dissecting root causes and missed signals.

Forensic Autopsies →
07

REMEMBER

What did we learn?

Reconstructed Day 0 to Day 90 checkpoints and persistent memory.

Historical Replay →
ROLE-BASED INTELLIGENCE

Why it matters to you

Four distinct lenses into the same intelligence engine, tailored to your operational mandate.

🛡️

Security Leaders & CISOs

Transform threat noise into defensible executive decisions.

  • Prioritize only weaponized threats that matter
  • Detect risk velocity acceleration before mass exploitation
  • Provide empirical, auditable justification for board reports
For Security Leaders →
🔍

Security Analysts & DFIR

Investigate faster with empirical evidence and historical context.

  • Knowledge Graph connecting 556+ entities and attack TTPs
  • Replay incident telemetry from Day 0 to Day 90
  • Native STIX 2.1 / TAXII 2.1 feeds for OpenCTI / Sentinel
For Security Analysts →
💻

Software & DevOps Engineers

Fix what actually matters with zero confidential code upload.

  • 100% in-browser private SBOM analysis (Zero upload)
  • Quantify net risk reduction before patching via Security Delta
  • Focus strictly on accelerated components in active use
For Engineering Teams →
🤖

AI & Agentic Security

Anticipate agent lateral movement, MCP hijack, and tool poisoning.

  • Track attack patterns targeting Model Context Protocol (MCP)
  • Simulate lateral agent movement and tool execution abuse
  • Stress-test emergency out-of-band kill-switch readiness
For AI Security →
🔒 STRICT SOVEREIGNTY

See what Hermes finds in your environment.

Analyze your software and SBOM privately in your browser. Your inventory never leaves your workstation.

SIMULATED ENVIRONMENT: ACME CORP Checked: Real-Time
Overall Exposure CRITICAL Active KEV component
Risk Trajectory ACCELERATING +14 pts / 24h velocity
Tracked Components 147 CycloneDX SBOM
Immediate Directives 2 Prescriptions Net gain: -42 pts HTS

100% client-side execution · No upload · Zero server persistence · Memory-only processing.

TRACK

Risk is not static.

A vulnerability is not just a static score. It is a living, evolving trajectory.

1. CURRENT STATE Risk Level (HTS)

Baseline severity at time t.

→
2. RISK VELOCITY Δrisk / Δt

Speed of weaponization escalation.

→
3. ACCELERATION Inflection Point

Crossing into active in-the-wild campaigns.

→
4. ARCHETYPE Trajectory Family

Categorized across 8 trajectory archetypes.

PREDICT

What happens next?

Falsifiable probabilistic forecasts bounded by strict deadlines and audited via the Brier score.

FC-2026-003 CONFIRMED ACCURATE

Will an unauthenticated automated exploit for ActiveMQ surface before Sept 25, 2026?

Predicted Probability: 82%
Brier Score: 0.0324

Confirmed accurate: Exploit framework published on GitHub 4 days ahead of deadline.

FC-2026-004 IN PROGRESS

Will CISA add Spug CVE-2026-90770 to KEV within 14 days of weaponization?

Predicted Probability: 78%
Oracle Status: Awaiting CISA release

Pending verification: Telemetry of active automated botnet propagation confirmed.

DECIDE

From intelligence to action

Hermes binds threat intelligence directly to decisive mitigation directives: Patch, Mitigate, Isolate, Replace, Accept, Monitor.

T0 IMMEDIATE (< 24h) CVE-2026-67593

Isolate ActiveMQ TCP port 61616 behind strict mTLS

Why? Public automated exploit wiping queues without authentication.

Residual Risk Delta: -42 pts HTS

T0 IMMEDIATE (< 24h) CVE-2026-90770

Restrict Spug management console WAN exposure

Why? Active in-the-wild botnet campaign concatenating shell commands.

Residual Risk Delta: -58 pts HTS

T1 TACTICAL (< 7d) CVE-2026-AGENT-MCP

Enforce read-only sandboxes on MCP filesystem bridges

Why? Indirect prompt injection triggering unauthorized file writes.

Residual Risk Delta: -35 pts HTS

COMMERCIAL TIERS

Transparent Cyber Risk Intelligence Pricing

Choose the level matching your operational scope: from open public intelligence to dedicated enterprise integration.

COMMUNITY
0 € Free

Understand the cyber world.

  • ✓ 1 498+ documents & playbooks DFIR
  • ✓ Observatoire global & scores HTS
  • ✓ Recherche libre CVE, KEV & EPSS
  • ✓ Analyseur SBOM basique dans le navigateur
Start Free
ENTERPRISE
Custom

Integrate Hermes into your workflow.

  • ✓ Serveur TAXII 2.1 dédié avec SLA
  • ✓ Licence d’exploitation du Graphe brut
  • ✓ Déploiement souverain On-Premise / Air-gapped
  • ✓ Intégration SSO d'entreprise & support prioritaire
Contact Sales

Ready to turn cyber risk into actionable decisions?

Audit your stack in 30 seconds with 100% in-browser privacy, or explore today’s intelligence.