The same autonomous tooling that enterprises are racing to deploy is now appearing on the other side of the breach, and it is appearing in every role at once. Recent reporting shows AI agent frameworks operating as malware, as criminal infrastructure and as an internal risk that security teams can only partly see. The common thread is not that attackers got smarter models; it is that agents turn exposed configuration mistakes into automated, autonomous intrusions, and existing defenses were built for humans at the keyboard.
The Agent Is Now the Payload
Carbonato, a newly reported botnet malware covered by BleepingComputer, targets insecure hosts running Docker daemons, installs the Hermes Agent AI framework and uses it to take control of the machine. That construction matters. Historically, a botnet's value came from the malware binary itself: the code that persisted, called home and executed commands. Here the enduring capability is an agent framework, an open-source component designed for legitimate orchestration, repurposed into a resident operator on the compromised host.
The Docker detail is the uncomfortable part. Exposed daemons are a well-known misconfiguration, one that defenders have warned about for years, but an agent changes what a single exposed port is worth. A human attacker who finds an open host must decide whether the target is worth the time, then work through the intrusion step by step. An agent installed on that host can survey, decide and act without that human pace. The vulnerable asset category is familiar; the exploitation economics are not.
Skimming at Criminal Scale
A second incident reported by BleepingComputer shows where that capability leads when it meets a profit motive. A financially motivated threat actor used open-source AI agent frameworks to attack hundreds of online retailers and steal more than 600,000 credit card records, infecting more than 100 sites with skimmers. This is not a novel technique. Web skimming has been a staple of e-commerce fraud for years. What is new is the breadth: hundreds of retailers and 100-plus infected sites inside a single campaign, sustained by agents that can locate, inject and manage skimmer code across many targets at once.
For US consumers, the consequence is ordinary and cumulative. Stolen card records feed fraud, and the operational cost lands on banks, retailers and the people whose accounts are used. For US technology companies, the exposure is structural. A mid-size online retailer rarely has a security team large enough to monitor every third-party script on its checkout pages. An attacker who can parallelize that reconnaissance and injection across hundreds of storefronts can exploit the long tail of commerce that no vendor is watching closely.
The Insider Problem Companies Bought Themselves
At Proofpoint's Protect event, covered by SiliconANGLE, the discussion shifted from whether enterprises will deploy AI agents to how they will govern them. The framing in that coverage is precise and worth taking seriously: internal agents act as insiders, with access to data, systems and inboxes. Attackers, meanwhile, use AI to write convincing phishing lures and chain exploits at machine speed.
That is the same pattern viewed from inside the perimeter. An agent with mailbox and system access occupies the position a malicious insider would need months to earn. It can read, summarize, forward and act, and it does so at a volume no human review process was designed to audit. The threat model most US enterprises built for insider risk assumed a person with human limits on attention and output. The agents they are now deploying do not share those limits, and the coverage notes that governance, not deployment, is where the debate has moved.




