ThreatDown says the Carbonato worm breaks into Docker daemons open on port 2375 and installs the open-source Hermes AI agent, then rescans nearby networks every five minutes to spread. An operator drives each infected host over Telegram.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives35
- Confidence50
Hunt.io says one operator brute-forced its way through more than 14,000 internet-exposed cameras in five weeks. The tooling was borrowed; the exposure did the work.
Perspective Coverage
6 publishers
- Builder
- Builder 34%
- Operator
- Operator 61%
- Investor
- Investor 5%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence64
The three flaws CISA listed on August 27 include a 2023 ownCloud bypass scored at CVSS 9.8. The only public exploitation account attached to any of them is a July 19 incident in which AI agents took root on an OpenAI worker node.
Perspective Coverage
4 publishers
- Builder
- Builder 26%
- Operator
- Operator 65%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence66
Hunt.io only found the intrusion because the operator left his staging directory browsable on port 8000 in Amsterdam. The scripts inside needed no passwords, just valid usernames and an ownCloud install nobody had updated.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 57%
- Investor
- Investor 10%
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap+8
- Incentives38
- Confidence60
Hunt.io says a threat actor left 298 files in an open directory in Thailand, including FortiGate and F5 exploit scripts written for 3BB and a MeshCentral backdoor that the cleanup script checked was still running.
Reality
- Evidence55
- Adoption30
- Hype gap+18
- Incentives60
- Confidence50
Hunt.io captured the operator's own server on June 3, 2026, while the intrusion was live. The files on it show password spraying across more than 55 internal hosts and a cleanup script written to erase everything except the MeshCentral agent.
Reality
- Evidence62
- Adoption45
- Hype gap−12
- Incentives60
- Confidence58
Hunt.io crawled the operator's own open directory and found the campaign output: 250 SonicWall SMA1000 appliances scanned, 168 leaking LDAP credentials, five Active Directory databases replicated in full.
Reality
- Evidence58
- Adoption80
- Hype gap−8
- Incentives55
- Confidence62
Hunt.io says a Chinese-speaking operator drove Claude Code, Alibaba Qwen and DeepSeek through an orchestration framework called SecFlow, splitting reconnaissance, exploitation and collection among specialist agents that fired only publicly documented exploits.
Reality
- Evidence46
- Adoption30
- Hype gap+18
- Incentives62
- Confidence45
Hunt.io rebuilt the framework from five directories the operators left open, and found the worker roles fixed while the model profile stays a swappable setting, with requests fronted by private proxies instead of vendor APIs.
Reality
- Evidence44
- Adoption50
- Hype gap+14
- Incentives62
- Confidence42
Check Point says a Chinese-speaking crew has been running custom Apache modules on compromised Brazilian federal, state and municipal web servers since mid-2025, so the address bar and the TLD tell a visitor nothing useful.
Perspective Coverage
3 publishers
- Builder
- Builder 23%
- Operator
- Operator 58%
- Investor
- Investor 19%
Reality
- Evidence67
- Adoption58
- Hype gap+26
- Incentives66
- Confidence65
Hunt.io says over 14,530 cameras fell to three parallel vectors. Two are the operator's problem. The third, the vendor's own P2P relay, opens on a serial number alone.
Reality
- Evidence58
- Adoption66
- Hype gap+10
- Incentives55
- Confidence52