Reading view
Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers
Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers, with a primary focus on cPanel and WHM deployments. The campaign first surfaced when malicious development versions were discovered across ten Packagist PHP packages tied to a legitimate PHP and DevOps [β¦]
The post Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure
NadMesh is a new, industrialβgrade Goβbased botnet that weaponizes more than 20 RCE vectors to hijack AI and MCP infrastructure at scale, combining autonomous scanning, exploit delivery, and credential harvesting in a single closedβloop platform. In early July 2026, researchers identified NadMesh as a highβvolume Go-written botnet that was aggressively deploying bot agents across internetβfacing [β¦]
The post New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Russian-Speaking Hacker Uses Gemini CLI to Deploy C2 Botnet in Six Minutes
A Russian-speaking threat actor tracked as βbandcamproβ used Google Gemini CLI as an end-to-end operational assistant to migrate a command-and-control server, deploy a replacement VPS, configure Cloudflare tunnels, and restore control of compromised endpoints within six minutes. The findings are based on an analysis of Gemini CLI session logs spanning March 19 through April 21, [β¦]
The post Russian-Speaking Hacker Uses Gemini CLI to Deploy C2 Botnet in Six Minutes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

AI-as-a-Service Botnet Routes Malicious Workloads Across Compromised Windows and Linux Hosts
The underground advertisement for the so-called Mycelium Framework reads like another featureβpacked botnet sales pitch: crossβplatform payloads, encrypted C2, persistence, exploit modules, credential theft, and lateral movement. Those building blocks are not new. What makes Mycelium notable is its advertised purpose to treat compromised endpoints not as disposable bots but as a capabilityβaware. AI compute [β¦]
The post AI-as-a-Service Botnet Routes Malicious Workloads Across Compromised Windows and Linux Hosts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
