# AI agent hacks national finance ministry, Botnet uses blockchain, Healthcare chain reopens Page: https://stenobird.com/podcast/cybersecurity-today-65508/ai-agent-hacks-national-finance-ministry-botnet-uses-blockchain-healthcare-chain-reopens Text version: https://stenobird.com/podcast/cybersecurity-today-65508/ai-agent-hacks-national-finance-ministry-botnet-uses-blockchain-healthcare-chain-reopens.md Podcast: [Cybersecurity Today](https://stenobird.com/podcast/cybersecurity-today-65508) Published: 2026-07-29T00:20:00+00:00 Episode link: https://cybersecuritytoday.libsyn.com/ai-agent-hacks-national-finance-ministry-botnet-uses-blockchain-healthcare-chain-reopens Audio file: https://traffic.libsyn.com/secure/cybersecuritytoday/AI_agent_hacks_national_finance_ministry_Botnet_uses_blockchain_Healthcare_chain_reopens.mp3?dest-id=679928 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/ai-agent-hacks-national-finance-ministry-botnet-uses-blockchain-healthcare-chain-reopens Duration seconds: 776 ## Resource Hospital ransomware fallout, blockchain botnet C2, and AI agent loose in Thailand's Finance Ministry. South Carolina's AnMed reopened some physician offices four days into a ransomware attack with phones, internet, and systems still offline, forcing manual processes and in-person medication refills, as broader healthcare ransomware totals hit 410 attacks worldwide in the first half of the year and a HIPAA Security Rule update was delayed to 2027 while class-action efforts began. Researchers report the Dysphoria IoT botnet moved command-and-control to blockchain name services and victim relays, making takedowns harder, with estimates above 200,000 bots and DDoS offerings up to 4 Tbps. Shared Claude chats were briefly indexed by Google, exposing sensitive data via public share links, before results stopped appearing. Hunt.io found attackers running a Hermes autonomous AI agent in Thailand's Finance Ministry, plus new "Hades" malware, suggesting reconnaissance. Stadler Rail refused a 10M CHF extortion demand tied to supplier data theft. 00:00 Introduction and Headlines 00:30 South Carolina Hospital Ransomware Attack 02:07 Healthcare Ransomware Crisis 03:25 IoT Botnet Uses Blockchain 05:40 Shared AI Chats Exposed 08:00 AI Agent Infiltrates Thailand Ministry 10:45 Swiss Train Maker Refuses Ransom 12:31 Closing Remarks ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/ai-agent-hacks-national-finance-ministry-botnet-uses-blockchain-healthcare-chain-reopens/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cybersecurity-today-65508/ai-agent-hacks-national-finance-ministry-botnet-uses-blockchain-healthcare-chain-reopens.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.