threat-intel New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens A Go botnet called NadMesh is actively targeting exposed AI services and cloud infrastructure, specifically seeking AWS keys, Kubernetes tokens, and Docker API access. The botnet, discovered by XLab and previously identified by Censys, uses a sophisticated scanning and exploitation strategy, leveraging tools like MCP t… The Hacker News · Jul 17, 2026 High CVE-2026-39987CVE-2026-41176CVE-2022-22947botnetcloud-securitydocker
malware TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development A new IoT botnet framework, TuxBot v3 Evolution, has been identified, leveraging LLM assistance during development. Developed by an Iranian-based developer, the framework is modular and includes features like DDoS-for-hi… Palo Alto Unit 42 · Jul 15, 2026 CVE-2022-1388CVE-2022-22965CVE-2020-8515