September 28, 2026
Bleeping Computer
New Carbonato malware uses AI agents to hijack exposed Docker hosts
BleepingComputer covers ThreatDown's discovery of Carbonato, a worm-like botnet that abuses unauthenticated Docker APIs to launch privileged containers and install the Hermes Agent AI framework. Operators send tasks through Telegram, and the AI agent runs commands on compromised hosts to collect AI API keys, SSH credentials, and access tokens.