The Go-based NadMesh botnet, discovered in early July 2026, is systematically targeting exposed AI services like ComfyUI, Ollama, and Gradio to harvest cloud credentials. According to QiAnXin's XLab, the botnet's dashboard claims the theft of 3,811 unique AWS keys. NadMesh exploits unauthenticated Model Context Protocol (MCP) deployments, Docker APIs, and Jenkins consoles to extract sensitive configuration files and Kubernetes tokens, highlighting a critical shadow IT security gap in rapid AI deployments.
Aug 10, 2026 · 8 sources
Aug 7, 2026 · 6 sources
Aug 10, 2026 · 3 sources
Aug 9, 2026 · 9 sources
Story comments
Loading comments…