Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

NadMesh Botnet Raids Exposed AI Servers for Cloud Credentials

NadMesh Botnet Raids Exposed AI Servers for Cloud Credentials
Photo by Tima Miroshnichenko on Pexels

The newly identified NadMesh botnet is scanning publicly reachable AI applications and infrastructure services for cloud credentials, Kubernetes tokens, and configuration files. Its targets include ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio, Docker, Jenkins, and Redis deployments that are exposed without sufficient authentication. ([thehackernews.com](https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html))

A newly documented Go-based botnet called NadMesh is showing why rapidly deployed artificial intelligence infrastructure has become an attractive target. Rather than concentrating only on processing power, the operation searches exposed services for credentials that can unlock cloud accounts, container registries, Kubernetes clusters, and additional business systems.

AI services become an entry point

NadMesh uses automated scanning to identify internet-accessible services associated with AI development and workflow automation. Reported targets include ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio, alongside conventional infrastructure such as Docker APIs, Jenkins consoles, Redis servers, Telnet, and SSH.

The malware searches compromised hosts for AWS keys stored in environment variables, Kubernetes service account tokens, Docker credentials, .env files, SSH access, and cloud configuration data. This means the initial server may be less valuable than the systems and services its credentials can reach.

An operator-controlled dashboard reportedly claimed possession of thousands of unique AWS keys, although researchers noted inconsistencies in several of its counters. These figures should therefore be treated as attacker claims rather than verified victim totals. Even so, observed scanning and deployment activity indicates that the botnet is operational and actively seeking poorly protected infrastructure.

How organizations can reduce exposure

  • Remove AI development interfaces and administrative APIs from the public internet.
  • Require strong authentication for Docker, Jenkins, Redis, workflow tools, and Model Context Protocol services.
  • Store cloud secrets in a managed vault instead of environment files or local configuration directories.
  • Use short-lived credentials and narrowly scoped Kubernetes service accounts.
  • Review SSH authorized keys, cron jobs, temporary directories, and unusual outbound connections.

Organizations running affected classes of services should pay particular attention to internet exposure on ports commonly associated with ComfyUI, Ollama, Gradio, and n8n. If compromise is suspected, administrators should isolate the host and remove malicious persistence before issuing replacement credentials. Otherwise, newly generated secrets could immediately be stolen again.

Expert view

I believe NadMesh represents a broader change in attacker economics. AI servers often combine powerful hardware, experimental software, administrative tools, and cloud credentials on the same machine. That combination creates an unusually valuable target.

In my view, companies should place AI development systems under the same security governance as production cloud infrastructure. Fast experimentation cannot justify public administrative interfaces, permanent access keys, or unauthenticated tools capable of executing commands. The central lesson is straightforward: an AI server is not merely a research workstation when it can authenticate to the rest of the enterprise. ([thehackernews.com](https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html))

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path