From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale
ID: 90f5a6a5-a954-5745-b040-6668adbec7b4
STIX ID: report--90f5a6a5-a954-5745-b040-6668adbec7b4
Feed Name: The Hacker News
Threat Score
A Go-based botnet named NadMesh is actively scanning exposed AI service endpoints (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) to harvest cloud credentials (including AWS keys) and Kubernetes tokens; QiAnXin XLab published analysis and operator dashboard screenshots showing thousands of keys, dozens of credential hauls and model inventories, and large deployment/scan counts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
