Summaries
Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.
Showing 1-1 of 1 results
| Date | Provider | Score | Summary |
|---|---|---|---|
| 07 Oct 2026, 11:33 PM | The Hacker News | 6.5 | PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
Lumen Black Lotus Labs detailed a campaign it calls Canto Incognito, where malware codenamed PoeLLM has infected more than 3,400 internet-facing servers since April 2026 to install XMRig and Iron cryptocurrency miners and connect victims to the Kryptex mining service. Targets are mostly AI/LLM infrastructure and dev tooling — LiteLLM, Gotenberg, Gitea, and Ivanti Sentry appliances — and the C2 address is hidden inside a poem hosted in a GitHub repository (github.com/ejejejdfbbebe, first commit April 13, 2026), with a few words swapped each time a new C2 is set up. Peak activity was mid-June 2026 at nearly 2,200 affected servers with about 800 active per day, concentrated in the U.S. and Western Europe; compromised hosts are reused as scanners and exploit servers, and recent traffic suggests experimentation with distributed SSH brute-force. Why: If you self-host LiteLLM, Gotenberg, Gitea, or similar tooling on a public IP, this is the concrete failure mode: your GPU/CPU gets rented out for someone else's Monero mining and your box becomes a scanner for the next victim. Decide this week whether your LLM gateway is reachable from the open internet at all, and whether it sits behind auth, a VPN, or an allowlist — the article shows exploitation of exposed deployments, not a patchable CVE. The poem-based C2 also means static blocklists of C2 domains will not help; detection has to look at outbound mining-pool traffic and unexpected outbound connections. |