cloud security4 articles
NadMesh Botnet Is Raiding Exposed AI Services for Cloud Keys, and the Numbers Don't Add Up
A Go-based botnet called NadMesh, discovered in early July 2025, systematically scans for exposed AI services (such as ComfyUI, Ollama, and n8n) to steal cloud credentials, Kubernetes tokens, and environment variable secrets, with the operator's own dashboard claiming over 3,800 harvested AWS keys. While the botnet prioritises AI service endpoints and MCP tools, the majority of its observed exploit traffic actually targets more traditional attack surfaces like Docker APIs and Jenkins consoles, with MCP exploitation accounting for less than 1% of recorded attempts. Defenders are urged to place exposed services behind authentication, check systems for persistence artefacts, and immediately revoke — not merely rotate — any credentials that may have been exposed.
Accenture Breached: Hacker Claims 35GB Haul Including Source Code and Azure Keys
Accenture has confirmed a data breach after a hacker claimed on PwnForums to have stolen 35 gigabytes of data, including source code, Azure access keys, RSA/SSH keys, and configuration files from the company. Accenture stated the incident has been remediated and that there is no impact on its operations, though it provided few further details. Security experts warn the stolen data could be leveraged for future attacks, given Accenture's close proximity to major enterprise clients' systems and infrastructure.
Meet CAI: The Cloud Worm That Mugs Other Malware Before Robbing You
A new cloud-targeting botnet called Cloud AI Infrastructure Attack Framework (CAI) has emerged, designed to steal credentials and mine cryptocurrency while actively eliminating competing malware like TeamPCP and PCPJack from compromised systems. It targets cloud-native tools such as Docker, Kubernetes, and Redis, using a centralized command-and-control structure and showing signs of LLM-assisted development. Security researchers warn that CAI's emergence alongside rival threat actors signals a growing and increasingly competitive landscape of malicious actors targeting cloud infrastructure and developer secrets.
AdaptHealth Blames Social Engineering After Patient Data Walks Out the Door
Medical equipment provider AdaptHealth suffered a cyberattack in which criminals used social engineering to compromise a third-party contractor and gain access to the company's cloud systems. Attackers stole sensitive patient data, including personally identifiable information, protected health information, and a password file linked to insurance billing, though Social Security numbers and payment details are believed to be unaffected. AdaptHealth disclosed the breach to the SEC on June 27, deeming it material due to the potential volume of data at risk, while investigations into the full scope of the incident are ongoing.