chiprook
← Security
SecuritySeptember 25, 2026, 03:10

Carbonato botnet uses AI agent to hijack exposed Docker hosts

Malwarebytes found a new botnet called Carbonato that infects Docker hosts with an unauthenticated API exposed on port 2375. It launches a privileged container, installs an SSH server with the operator's key, and deploys the Hermes Agent AI framework with an agent named GH0ST to harvest keys and tokens via Telegram.

Carbonato botnet uses AI agent to hijack exposed Docker hosts
#Malwarebytes#Docker#HermesAgent#Telegram
Read next
Security

'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

Security

MacSync malware uses public iCloud calendars to deliver new payloads

Security

Apache Tomcat 11.0.26 fixes CVE-2026-77762 HTTP/2 trailer leak

Security

SectopRAT Returns, Hiding Inside a Legitimate Application