THEMETASEC

Cybersecurity News, Aggregated

AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway

Security Affairs · 1 hour ago Vuln

CARBONATO exploits exposed Docker daemons, installs an AI agent, steals API keys and spreads across networks with autonomous command execution. CARBONATO is a Docker-based botnet that has been active since at least October 2024. ThreatDown discovered the operation after finding an unauthenticated container registry exposed to the internet. The registry contained the attackers’ entire toolchain […]

Read full story at Security Affairs →