logo

From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale

ID: 90f5a6a5-a954-5745-b040-6668adbec7b4

STIX ID: report--90f5a6a5-a954-5745-b040-6668adbec7b4

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-07-10

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

A Go-based botnet named NadMesh is actively scanning exposed AI service endpoints (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) to harvest cloud credentials (including AWS keys) and Kubernetes tokens; QiAnXin XLab published analysis and operator dashboard screenshots showing thousands of keys, dozens of credential hauls and model inventories, and large deployment/scan counts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.