https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/
Carbonato targets exposed Docker daemons Carbonato is a botnet malware targeting Docker APIs exposed on port 2375 without authentication. It deploys a privileged container, opens reverse SSH access, installs the Hermes Agent framework with a GH0ST persona, reports via #Telegram, and persists through cron, systemd, rc.local, and OpenRC.