botnethigh
NadMesh Botnet Targets Exposed AI Services for Cloud Credentials
A newly identified botnet written in Go, dubbed NadMesh, is actively scanning for and exploiting exposed AI services. The botnet specifically targets cloud environments, seeking to steal AWS keys and Kubernetes tokens from vulnerable AI platforms. Researchers have observed it scanning for services like ComfyUI and Ollama, which are often deployed without adequate security measures.