← All campaigns

Tag

docker

2 campaigns

Compare these two campaigns →

One Operator, Every LLM Key They Could Reach

For three months, one attacker chased a single goal — free AI compute, taken from the machines they broke into. Wherever they landed, they went after two things: cloud login keys they could point at a provider's hosted AI models, and the raw API keys that developers leave sitting in configuration files.

2026-10-02

TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking

Docker exposes a management interface, the Docker daemon API, that lets you create, start, and control containers. When it is accidentally published to the internet with no authentication, anyone who can reach that port can take over the host underneath it. We watched a fully automated toolkit do exactly that in about 45 seconds.

2026-06-29