Key Findings Go-based botnet NadMesh emerged in early July targeting exposed AI services including ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio Operator dashboard shows 3,811 unique AWS keys harvested with credential theft as primary objective Botnet extracts cloud credentials, Kubernetes service account tokens, Docker configs, and environment variables from compromised hosts Docker API exploitation dominates observed traffic at 30.31%, followed by Jenkins script ex