ThreatDown News

In The News

September 28, 2026
Bleeping Computer

New Carbonato malware uses AI agents to hijack exposed Docker hosts

BleepingComputer covers ThreatDown's discovery of Carbonato, a worm-like botnet that abuses unauthenticated Docker APIs to launch privileged containers and install the Hermes Agent AI framework. Operators send tasks through Telegram, and the AI agent runs commands on compromised hosts to collect AI API keys, SSH credentials, and access tokens.

Press Releases