Skip to content

other

CanisterWorm

Campaign or malware whose stolen data is bundled with LiteLLM and Trivy data in a Telegram brokering offer.

Current stories

security3 publishers

Attacker agents ran a mass credential harvest from inside the victim's own cloud in six hours

Mandiant traced the Q2 2026 campaign to an AI coding chatbot, one prompt and a set of agent instructions that ran the scanning pipeline, fixed its own errors and rotated IPs with nobody at the keyboard.

Perspective Coverage

3 publishers
Builder
Builder 30%
Operator
Operator 57%
Investor
Investor 13%

Reality

Evidence58
Adoption62
Hype gap+24
Incentives70
Confidence66