Security News

Docker expands its trusted container offerings
2021-05-28 19:51

That's why Docker has expanded and improved its trusted content offerings for software developers with the launch of the Docker Verified Publisher Program. Docker, which shed its container engine and control plane to Mirantis in 2019, has been focusing on improving and securing its Docker Hub, the most popular service for finding and sharing container images.

How to use Docker Bench for Security to audit your container deployments
2021-04-08 17:38

Docker Bench for Security is a simple way of checking for common best practices around your Docker deployments in production. One such tool is a pre-built container, called Docker Bench for Security-it does a great job of auditing your container host and the currently running deployments.

Malicious Docker Cryptomining Images Rack Up 20M Downloads
2021-03-30 20:22

At least 30 malicious images in Docker Hub, with a collective 20 million downloads, have been used to spread cryptomining malware, according to an analysis. The malicious images have raked in around $200,000 from cryptomining, according to Aviv Sasson, researcher with Palo Alto Networks' Unit 42, who found and reported the malicious activity.

Docker Hub images downloaded 20M times come with cryptominers
2021-03-29 18:30

Researchers found that more than two-dozen containers on Docker Hub have been downloaded more than 20 million times for cryptojacking operations spanning at least two years. Docker Hub is the largest library of container applications, allowing companies to share images internally or with their customers, or the developer community to distribute open-source projects.

New Docker Container Escape Bug Affects Microsoft Azure Functions
2021-01-27 07:59

Cybersecurity researcher Paul Litvak today disclosed an unpatched vulnerability in Microsoft Azure Functions that could be used by an attacker to escalate privileges and escape the Docker container used for hosting them. Following disclosure to Microsoft, the Windows maker is said to have "Determined that the vulnerability has no security impact on Function users, since the host itself is still protected by another defense boundary against the elevated position we reached in the container host."

Analysis of 4 Million Docker Images Shows Half Have Critical Vulnerabilities
2020-12-02 14:16

Container security company Prevasio has analyzed 4 million public Docker container images hosted on Docker Hub and found that over half of them had critical vulnerabilities and thousands of images included malicious or potentially harmful elements. The cybersecurity firm used its Prevasio Analyzer service to analyze all the container images on Docker Hub, the largest library and community for container images.

Misconfigured Docker Servers Under Attack by Xanthe Malware
2020-12-01 21:51

Researchers first discovered Xanthe targeting a honeypot, which they created with the aim of discovering Docker threats. Misconfigured Docker servers are another way that Xanthe spreads.

Canonical Publishes Secure Container Application Images on Docker Hub
2020-11-24 15:31

Canonical, the publisher of the Ubuntu Linux distribution, announced on Tuesday that it has made available long-term support container images on Docker Hub, promising up to 10 years of security maintenance. Some of these hardened images have a five-year free security maintenance period - the standard security maintenance of the underlying Ubuntu LTS - while customers of Ubuntu Pro are provided access to ten-year Extended Security Maintenance images.

Docker Enterprise Container Cloud helps enterprises ship code faster on public and private clouds
2020-09-18 00:30

Docker Enterprise Container Cloud offers enterprises unprecedented speed to ship code faster on public clouds and on premise infrastructure. "Docker Enterprise Container Cloud and Lens will enable businesses to streamline delivery of hundreds of daily deployments across thousands of apps, overcoming the complexity of Kubernetes development at enterprise scale," said Mirantis customer Don Bauer, Docker Captain and VP Technology Services / DevOps Manager.

Doki Backdoor Infiltrates Docker Servers in the Cloud
2020-07-30 17:00

A fresh Linux backdoor called Doki is infesting Docker servers in the cloud, researchers warn, employing a brand-new technique: Using a blockchain wallet for generating command-and-control domain names. The campaign starts with an increasingly common attack vector: The compromise of misconfigured Docker API ports.