The Go-based NadMesh botnet, discovered in early July 2026, is systematically targeting exposed AI services like ComfyUI, Ollama, and Gradio to harvest cloud credentials. According to QiAnXin's XLab, the botnet's dashboard claims the theft of 3,811 unique AWS keys. NadMesh exploits unauthenticated Model Context Protocol (MCP) deployments, Docker APIs, and Jenkins consoles to extract sensitive configuration files and Kubernetes tokens, highlighting a critical shadow IT security gap in rapid AI deployments.
Sep 28, 2026 · 6 sources
Sep 25, 2026 · 4 sources
Sep 30, 2026 · 3 sources
Sep 30, 2026 · 4 sources
Story comments
Loading comments…