Follow the latest coverage, related explainers and connected technology stories.
Black Lotus Labs researchers uncovered a covert mining campaign that exploited more than 3,400 exposed servers, including systems running LiteLLM and Ollama, and turned infected devices into platforms for scanning new targets and carrying out attacks. The malware uses an unusual mechanism to extract command-and-control server addresses from hidden words in a poem hosted on GitHub.