Carbonato Malware Exploits Docker Hosts To Operate Hermes AI Agent Framework
Security researchers reveal Carbonato botnet attacks exposed Docker daemons to deploy Hermes AI Agent, enabling Telegram controlled operations and credential collection.
Security researchers reveal Carbonato botnet attacks exposed Docker daemons to deploy Hermes AI Agent, enabling Telegram controlled operations and credential collection.
Security researchers identify compromised MemTensor npm and PyPI packages delivering sckit malware designed to steal developer credentials and sensitive cloud data.
Security researcher Patrick Wardle has demonstrated a Mac version Muse issue that could redirect AI assistant dictation and expose user granted access if a device is already compromised.
Security researchers have uncovered a malicious npm package called indexed-btree that concealed malware inside runtime code, highlighting changing software supply chain attack methods.
Security researchers identify ChainScript RAT delivered through ClickFix lures, using Polygon smart contracts to rotate command and control infrastructure.
Anthropic details how threat actors used Claude for cyber attacks, surveillance, influence campaigns, and autonomous operations while outlining actions taken to disrupt the activity.
Anthropic says it disrupted a Russian linked cyber espionage campaign that used Claude to automate malware rebuilding, phishing operations, and infrastructure management.
Symantec reports that threat actors are abusing the trusted Node.js runtime to deploy malware in attacks targeting government agencies, technology firms, hotels, and financial organizations.
International authorities and cybersecurity partners have disrupted the long running Sality botnet by using a P2P sinkhole operation to block malware payload delivery.
ESET researchers have uncovered the GuardBreaker technique used by Russia aligned UAC 0099 to disrupt AI assisted malware analysis by embedding safety sensitive prompts in malicious code.