New Carbonato malware uses AI agents to hijack exposed Docker hosts
Summary
Carbonato is a new botnet malware that exploits insecure Docker hosts (Docker is a containerization tool that packages applications) by installing an AI agent framework called Hermes Agent to take control of them. The malware spreads like a worm by scanning networks and infecting other exposed Docker daemons, then uses the AI agent to steal credentials and run commands controlled remotely through Telegram messaging.
Solution / Mitigation
To prevent infection, the researchers recommend keeping Docker daemon APIs off the network and requiring authentication on registries.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/
First tracked: September 24, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 85%