New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
Summary
NadMesh is a Go botnet (malware written in the Go programming language) that hunts for exposed AI services like ComfyUI and Ollama to steal cloud credentials, Kubernetes tokens (authentication keys for container orchestration systems), and access to AI models. The botnet prioritizes exploiting MCP (Model Context Protocol, a framework for AI tools), Docker APIs, and Jenkins systems, with observed attack traffic showing Docker vulnerabilities account for the largest portion of exploitation attempts.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
First tracked: July 17, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 92%