Toggle light / dark theme

Get the latest international news and world events from around the world.

Log in for authorized contributors

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that’s targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent.

“The implant installs the framework unchanged, then overwrites its SOUL.md persona file,” ThreatDown said. “The 39-line prompt directs it to execute tasks received through Telegram, maintain persistence, and collect credentials.”

At a high level, the botnet breaks into Docker daemons exposed without authentication on port 2,375 and scans neighboring networks every five minutes to propagate further. On each host, it installs Hermes Agent with instructions to follow operators’ Telegram commands.

Over 16,000 Supabase databases expose PII, passwords, auth tokens

Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens.

Based on the analysis of table schemas, researchers at cyber risk management company UpGuard believe that a very small set of the exposed information includes credit card data.

Supabase is an open-source development platform built around PostgreSQL that provides developers with a range of backend services to build and launch apps and websites faster.

JadePuffer agentic AI attacks target Azure, destroy cloud resources

The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.

The malware emerged in July, with researchers at cloud security company Sysdig highlighting that it uses AI agents to automate the entire attack chain, from reconnaissance, credential theft, and lateral movement to persistence and data encryption.

Shortly after, the company noted that JadePuffer expanded its focus to AI assets, training datasets, and vector databases, using a tool called EncForge.

US soldier gets 70 months in prison for extorting 10 tech, telecom firms

A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.

21-year-old Cameron John Wagenius (also known online as ‘kiberphant0m’ and ‘cyb3rph4nt0m’) was arrested in Texas in December 2024.

He pleaded guilty in February 2025 to hacking AT&T and Verizon after being charged on two counts of unlawfully transferring confidential phone records, and in July 2025 to multiple counts of aggravated identity theft, conspiracy to commit wire fraud, and extortion related to computer fraud.

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026–35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.

Google’s Mandiant and Threat Intelligence Group (GTIG) say this new technique has allowed the threat actor to once again target PeopleSoft servers that had not applied security updates and instead blocked access to the vulnerable PSEMHUB endpoint using a WAF.

On June 10, BleepingComputer first reported that the ShinyHunters extortion gang was targeting Oracle PeopleSoft servers using a zero-day vulnerability, allowing them to steal data from 100 organizations.

Cloudflare fixes Containers cross-tenant flaw exposing customer data

Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers’ containers on the same physical host.

Cloudflare Containers is a service available on the Workers Paid plan that lets developers run containerized applications on Cloudflare’s infrastructure, alongside Cloudflare Workers.

Developers and companies building applications on Cloudflare typically use it, including those running backend services, processing jobs, and code execution environments.

How to Refine Houdini Destruction According to Former Pixar FX Artist

A former Pixar FX Technical Director explains how his Multi-Layered RBD Simulation workflow lets Houdini artists add fractures and secondary detail while preserving approved destruction motion.

Full interview and research.


Destruction simulations can become extremely expensive to revise once their overall movement has been approved. Changing the fracture pattern or behavior of one area may alter piece indexing, constraints, collisions, and the motion of surrounding geometry, forcing artists to recalculate work that a director already liked. Former Pixar FX Technical Director Jae Jun Yi developed a layered Houdini workflow intended to make those increasingly specific production notes easier to address.

Presented at SIGGRAPH 2026, Multi-Layered RBD (Rigid Body Dynamics) Simulation begins with a relatively simple base simulation focused on composition and large-scale motion. Artists can then select individual pieces manually or through conditions such as size, velocity, impact strength, and collision events. Those pieces are fractured again, inherit the approved movement of their parents, and transition into a new dynamic simulation only when an artist-defined trigger is reached.

In this interview, Yi explains how identifiers, transform attributes, activation states, constraints, and collision adjustments maintain physical continuity between layers. He also discusses the workflow’s art-direction controls, its limitations for highly interconnected or interactive destruction, and his preference for extending Houdini’s familiar RBD toolset rather than creating a specialized system that other artists would struggle to understand.

Industrial AI Pilot Revenue Hides A Widening Production Gap

Most industrial AI pilots are booked as if they are the start of a multi-year platform deal. In reality, most never become one.

RAND and MIT’s 2026 analysis puts the failure rate at 80.3%. Multiple studies converge on 70–88% of AI pilots never reaching production.

The bigger financial risk is the scale-up cost. Moving a successful pilot into production typically costs 250–400% more than the pilot itself. A $100,000 pilot can need $300,000–$800,000 more to go live.

Most buyers do not reserve that budget going in. When the real number appears after the fact, the project dies for lack of an approved line item — not for lack of results.

Vendors whose revenue holds up past year one tend to price the pilot and the scale-up as separate milestones, and tie part of the scale fee to actual production usage.

Pilot bookings are not a leading indicator of platform revenue. Production conversion is.

Full analysis:

/* */