Carbonato Botnet Deploys AI Agents on Compromised Docker Hosts
A botnet campaign has been discovered installing AI agents on vulnerable Docker hosts to execute commands via Telegram and steal API keys from exposed AI…
Immediately audit exposed Docker instances: restrict remote access, enforce strong authentication, and monitor Telegram API logs on your systems. Regularly audit API keys stored or accessible within containers, especially in development and staging environments.