Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Vendors and products
- Docker
- Reported by
- 1 outlet
The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts.
We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what CyberBrief adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-28 20:23 UTC
Related stories
- One Packet Can Crash OT Servers in Industrial Sectors
Dark Reading · 2026-09-28
- Times Car confirms data breach affecting 6.6 million user accounts
BleepingComputer · 2026-09-28
- JadePuffer crims hijacked Azure identities and used them to blow up cloud resources
The Register · 2026-09-28
- ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
The Record · 2026-09-28
- Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
The Hacker News · 2026-09-28