CARBONATO hijacks exposed Docker daemons, then runs an AI agent to loot credentials and fund its own model access.
US and European agencies sinkholed the 23-year-old Sality botnet by poisoning the peer lists its infected machines trust.
The FBI seized QScan and QTRouter, Chinese hacking platforms behind intrusions into NASA, the Federal Reserve, and the Senate.
Kaspersky finds a downloader pushed through built-in firmware updaters of Android dashboards, tied to the MoYu Group.
Fortinet's FortiGuard Labs uncovered Evooo1Bot, a Mirai-derived Linux botnet that turns hacked edge devices into SOCKS5 proxies.
Check Point links nearly 2,000 hacked WordPress sites to fake-captcha malware delivery.
Unit 42 documents Kimwolf v7, a rebuild that hides DDoS floods behind browser fingerprints and Ethereum domains.
Researchers discovered the NadMesh botnet, which targets exposed AI infrastructure to steal cloud keys and Kubernetes tokens.