security2 publishers
Carbonato malware installs an AI agent on Docker hosts left exposed on port 2375
Malwarebytes' ThreatDown found Carbonato, a worm that reaches Docker daemons open on port 2375 without authentication and installs the Hermes AI agent to run attacker commands. Operators drive it from a Telegram chat, and the recovered evidence spans October 2024 to August 2026.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives35
- Confidence55