< BACK TO NEWS
importantSYS.SOURCE: The Hacker News• 2026-09-28T17:16:00+05:30

Carbonato Botnet Exploits Unsecured Docker Daemons to Deploy AI-Powered Telegram-Controlled Hermes Agent

Carbonato Botnet exploits unauthenticated Docker daemons to deploy an AI-powered Hermes Agent framework, enabling Telegram-controlled remote access and persistence. The malware uses AI automation for attack chain execution, highlighting growing threats in cloud and container security.

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent.

"The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through

Read original article

*** END OF TRANSMISSION ***