CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2778

As cited

Copy frozen at (site build).

threat intel

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

A Go-based botnet named NadMesh emerged in early July 2024, targeting exposed AI services to harvest AWS keys and Kubernetes tokens. The malware uses Shodan scanning to identify vulnerable instances of tools like ComfyUI, Ollama, and Gradio that are often deployed without adequate firewall protection. The operator's dashboard reportedly tracks over 3,800 unique AWS credentials stolen from these compromised systems.

Why it matters: Organizations deploying AI services and container orchestration platforms need immediate inventory and network segmentation of these tools, as exposed credentials grant direct access to cloud infrastructure and data stores.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

A Go-based botnet named NadMesh emerged in early July targeting exposed artificial intelligence (AI) services and collecting cloud credentials, including over 3,800 AWS keys according to the attacker's dashboard. The malware uses a Shodan harvester to scan for and compromise commonly exposed AI tools including ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio. The article text is incomplete and does not provide full details about the threat.

Why it matters: Organizations running AI services, model runners, and workflow builders on exposed infrastructure face immediate credential theft and lateral movement into cloud environments; practitioners should audit firewall rules and credential exposure for these common tools.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

A Go-based botnet named NadMesh emerged in early July targeting exposed artificial intelligence (AI) services and collecting cloud credentials, including over 3,800 AWS keys according to the attacker's dashboard. The malware uses a Shodan harvester to scan for and compromise commonly exposed AI tools including ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio. The article text is incomplete and does not provide full details about the threat.

Why it matters: Organizations running AI services, model runners, and workflow builders on exposed infrastructure face immediate credential theft and lateral movement into cloud environments; practitioners should audit firewall rules and credential exposure for these common tools.

VendorsAmazon Web ServicesKubernetes
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary