CriticalSecurity & Privacy
Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
Carbonato shows how attackers are now weaponizing AI agent frameworks to automate post-compromise activity, using Telegram-controlled commands to run on exposed Docker hosts and harvest AI API keys. For CIOs and IT leaders, this raises the stakes for container security and secrets management: misconfigured infrastructure can become both a compute resource for botnets and a path to steal high-value AI credentials that could drive further fraud, data exposure, or cloud cost abuse.
