Security News

Nginx will need patches, hotels exposed by their own security tools, Docker containers dinged, and more
2019-06-03 06:03

Another week of security mishaps is in the books Roundup Here's a quick summary of news in the world of information security beyond everything we've already covered.…

Unpatched Docker bug allows read-write access to host OS
2019-05-31 11:58

Suse developer Aleksa Sarai has uncovered a bug in the way that the container framework handles path names.

Researcher Describes Docker Vulnerability
2019-05-30 15:18

No Patch Available Yet, But Exploiting the Flaw Would Be 'Challenging'A security researcher has found a significant flaw all versions of Docker, an open source container platform, that can give...

Docker Vulnerability Gives Arbitrary File Access to Host
2019-05-29 18:10

A newly disclosed vulnerability in Docker could be exploited by a malicious attacker to escape the container and gain arbitrary read/write file access on the host with root privileges. read more

Contain yourself, Docker: Race-condition bug puts host machines at risk... sometimes, ish
2019-05-29 02:05

Tricky to exploit in the real world, which is good because no official fix is available yet A vulnerability in all versions of Docker can be potentially exploited by miscreants to escape...

No Root Password for 20% of Popular Docker Containers
2019-05-22 15:14

An analysis of 1,000 popular Docker containers revealed that nearly 20% of them have nulled root passwords, Kenna Security says.  read more

Device Authority enhances KeyScaler for Microsoft Azure IoT Hub DPS and Docker
2019-05-14 23:30

Device Authority, a global leader in Identity and Access Management (IAM) for the Internet of Things (IoT), announced two of its latest KeyScaler platform developments with Microsoft Azure IoT Hub...

Alpine Linux Docker Images Shipped for 3 Years with Root Accounts Unlocked
2019-05-09 17:06

Alpine Linux Docker images available via the Docker Hub contained a critical flaw allowing attackers to authenticate on systems using the root user and no password.

Hard-Coded Credentials Found in Alpine Linux Docker Images
2019-05-09 13:14

For the past three years, Alpine Linux Docker images have been shipped with a NULL password for the root user, Cisco’s Talos security researchers have discovered.  read more

Week in review: Docker Hub breach, identifying malware in embedded systems, CCPA implementation
2019-05-05 18:00

Here’s an overview of some of last week’s most interesting news and articles: Mozilla will block Firefox add-ons that contain obfuscated code Mozilla has announced that, starting from June 10,...