EventCybersecuritySeptember 28, 2026

Carbonato botnet hijacks Docker hosts to run Hermes AI agent

Read original source →thehackernews.com

ThreatDown found the botnet breaking into Docker daemons exposed without authentication on port 2375, installing Hermes Agent and overwriting its SOUL.md with a 39-line prompt for Telegram-controlled tasks. It spreads via privileged containers, reverse SSH tunnels to a Costa Rica relay, and rescans nearby networks every five minutes.

2 sources

More stories today

Open the live feed