[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqt0B7ZTfHIBfHuqhElub25c04dEJOK0rNfubKnJOwfQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"bdedba1d-94bd-42c8-96f5-d72a82446d0d","exposed-docker-daemons-hijacked-by-ai-powered-telegram-botnet","b2746fe9-5d14-452b-8bd7-843b13201cb5","Exposed Docker Daemons Hijacked by AI-Powered Telegram Botnet","The Carbonato botnet exploits a critical and avoidable misconfiguration: Docker daemons left exposed to the internet without authentication. By gaining unauthenticated access, attackers can spin up privileged containers that effectively have root-level access to the underlying host, enabling worm-like lateral spread across environments. The use of an AI agent (Hermes) controlled via Telegram demonstrates how attackers are weaponizing legitimate open-source tools to evade traditional detection. This incident highlights that exposing container orchestration APIs without proper access controls is equivalent to leaving a server room unlocked — any attacker can walk in and take control.","**Immediate actions:**\n- Audit all Docker daemon configurations and immediately disable TCP socket exposure unless TLS client authentication is enforced.\n- Scan your perimeter for exposed Docker APIs (port 2375\u002F2376) using tools like Shodan or internal vulnerability scanners and remediate findings within 24 hours.\n\n**Long-term improvements:**\n- Enforce a policy that Docker daemons must use Unix sockets locally and require mutual TLS authentication for any remote access.\n- Implement a container security baseline (e.g., CIS Docker Benchmark) as part of your standard provisioning pipeline to prevent future misconfigurations.\n- Restrict container privileges by default — never allow privileged containers unless explicitly reviewed and approved.\n\n**Detection measures:**\n- Monitor Docker daemon logs and alert on unexpected container creation events, especially those using the `--privileged` flag.\n- Deploy network monitoring to detect unusual outbound connections to messaging platforms (e.g., Telegram API endpoints) originating from container workloads.",[12,13,14,15,16,17,18,19,20],"CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 12: Network Infrastructure Management","CIS Docker Benchmark v1.6","NIST SP 800-190: Application Container Security Guide","NIST AC-3: Access Enforcement","NIST CM-6: Configuration Settings","NIST SI-3: Malicious Code Protection","MITRE ATT&CK T1610: Deploy Container","MITRE ATT&CK T1609: Container Administration Command","published","2026-09-28T19:22:07.979674+00:00","2026-09-28T19:22:07.687+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fcarbonato-botnet-compromises-docker.html","carbonato-botnet-compromises-docker-hosts-to-deploy-telegram-controlled-hermes-a-a2739f","Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":42,"name":43,"slug":44,"description":45,"color":46},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]