Advisory on CARBONATO Botnet Campaign Targeting Exposed Docker Daemons

Imported from official source

Announcement

Security researchers have identified a botnet campaign known as CARBONATO targeting Docker hosts with unauthenticated Docker Remote APIs exposed to the Internet. Organisations operating Docker environments are advised to review their configurations and assess potentially exposed systems for signs of compromise.

Read the original at the source: https://www.csa.gov.sg/alerts-and-advisories/advisories/ad-2026-012

Officially imported this from Cyber Security Agency of Singapore’s own source. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Cyber Security Agency of Singapore — imported from official source
Official source
https://www.csa.gov.sg/alerts-and-advisories/rss.xml RSS
Imported
October 03, 2026 20:41
Versions
1 recorded
Identity
urn:isomer:resource:422640

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.