A newly discovered Go-based botnet dubbed NadMesh is systematically hunting exposed artificial intelligence services and Model Context Protocol (MCP) servers, harvesting cloud credentials at scale and signaling a shift from indiscriminate worm behavior toward an industrial-grade, return-on-investment-driven attack platform. Uncovered in early July 2026 by researchers at QiAnXin XLab, the malware combines automated internet-wide reconnaissance with more than 20 distinct remote code execution vectors to compromise AI infrastructure that has been left accessible on the open internet.
Continue reading
The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in✓ Signed in — this article isn’t included in your current plan.