Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics

Gradio stories

Jul 17, 2026

NadMesh Botnet Harvests 3,800+ Cloud Credentials by Targeting Exposed AI Services

A Go-based botnet called NadMesh, discovered in early July 2026, is systematically scanning for and exploiting exposed AI services including ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio to steal cloud credentials. The operator's dashboard claims to have collected 3,811 unique AWS keys along with Kubernetes tokens.

Jul 17, 2026·5 sources
00

Top claims

  • ▪The NadMesh botnet operator's dashboard, analyzed by QiAnXin's XLab, claims the collection of 3,811 unique AWS keys.
  • ▪The NadMesh botnet's central controller coordinates bots using HTTP APIs, seeding them with more than 90 cloud provider address ranges and falling back to random /24 ranges when the task queue is empty.
  • ▪The NadMesh botnet deploys more than 20 exploitation vectors, including Kubernetes API abuse via pods with hostPath mounts and Docker API misuse to launch containers with host networking.

Topics

Cloud securityAI tools & productsAI securityAI privacy & surveillance

Featured Stories

OpenAI pauses development of Astra AI model over critical cybersecurity capability concerns

OpenAI pauses development of Astra AI model over critical cybersecurity capability concerns

Aug 7, 2026·2 sources