Act
active
Carbonato malware uses AI agents to hijack exposed Docker hosts
- Engineer — Act: If you expose Docker daemon sockets (TCP port 2375/2376) without auth, audit immediately and either bind to localhost-only or enforce TLS mutual auth; scan for Hermes Agent processes or unexpected AI framework containers on Docker hosts.
- SOC/IR — Plan: Build detections for unexpected container spawns or Hermes Agent framework activity on Docker hosts; hunt for outbound C2 from container workloads as a new campaign variant to cover this quarter.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.