A newly discovered botnet called Carbonato is breaking into poorly secured Docker hosts and installing the Hermes Agent AI framework, which then carries out the operators' orders on compromised machines, according to ThreatDown.
The enterprise security company found the malware in an unauthenticated Docker registry that held nearly 60 repositories and 4.3 GB of image data. The operational evidence recovered from it covers the period from October 2024 to August 2026. The archive also held details on a separate campaign that pushed counterfeit cryptocurrency wallet apps, a lure that has recently shown up in Mac-focused stealer campaigns as well.
Researchers at Zenity Labs have disclosed three vulnerabilities in Salesforce Agentforce, the company's platform for AI agents. Attackers could have abused the flaws to turn trusted agents against their own organizations. The agents could be made to leak sensitive customer relationship management (CRM) data or to send phishing messages to employees.
The researchers call the set of bugs SalesBleed. According to Zenity Labs, two of the flaws allowed zero-click data exfiltration. The third let an attacker weaponize an Agentforce agent to spread phishing inside a company.
Zenity Labs reported the issues to Salesforce on June 1. Salesforce confirmed that all three had been fixed by August 19.
AI agents run by OpenAI broke into a Medicare statistics portal run by the Australian government. They also probed public data providers in several countries for vulnerabilities. The agents were carrying out information-retrieval tasks for a research project at the time.
Australian Prime Minister Anthony Albanese confirmed the breach on September 24. The portal belongs to Services Australia, the federal agency that delivers health and social payments, including Medicare, the country's public health insurance scheme. The unauthorized access took place on June 18 and exposed both public and non-public data.
A detour through a URL scanner
Much of the wider activity came to light through Transluce, a nonprofit research lab. It analyzed public records from urlquery.net, a URL scanning service. The lab found that when the agents could not reach a site directly, they used the service's remote browser system to fetch the data instead.
Guy Fawkes News is financed by advertising. You can choose how you want to use this website:
With advertising: we load an advertising script from a third-party ad network. The ad network may set cookies, use your IP address and device information, and may process data outside the EU. We also count your visits for our own visitor statistics (with a random ID stored in your browser).
Ad-free for €0.99 per month: no advertising and no advertising tracking. Cancel at any time.
You can change your decision at any time via "Cookie Settings" at the bottom of every page.