Tag: container
-
Uptime Kuma 2.5.0 waits two weeks before trusting a new npm package
Uptime Kuma checks whether a website, a Docker container, a DNS record, or a Steam game server is still answering, and pushes a message to Telegram, Slack, or email when one … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/04/uptime-kuma-2-5-0-cooldown-npm-updates/
-
YAML’d
H/T to Trey Blalock from Verification Labs :: Penetration Testing Specialists – Trey Blalock GCTI, GWAPT, GCFA, GPEN, GPCS, GCPN, CRISC, CISA, CISM, CISSP, SSCP, CDPSE. This comic is a meme template based on a “Fortune Teller” comic created by Jon Sullivan per that fount of knowledge, Google. First seen on securityboulevard.com Jump to article:…
-
BellSoft takes on Dockerfile sprawl with Hardened Builder
BellSoft’s Hardened Builder lets Paketo Buildpacks users build zero-CVE container images on hardened base images, reducing security toil without changing application code. First seen on techtarget.com Jump to article: www.techtarget.com/searchapparchitecture/news/366645989/BellSoft-takes-on-Dockerfile-sprawl-with-Hardened-Builder
-
Containerd – Kritische Schwachstelle in Open-Source-Software für Container-Runtime
First seen on security-insider.de Jump to article: www.security-insider.de/containerd-schwachstellen-kubernetes-cri-plugin-a-ff000657e310717ca6ed5b9de656deab/
-
Hackers Can Exploit RabbitMQ OAuth Flaw to Access Every Message, Queue, and User
Security researchers have disclosed two access-control vulnerabilities in RabbitMQ, the open-source message broker used in an estimated 8% of all containers running today, that could allow attackers to seize full administrative control of a broker or silently map out sensitive queue data across shared tenants. Both flaws were discovered by Miggo Security’s autonomous research system,…
-
15-Year-Old GhostLock Linux Kernel Vulnerability Enables Root Access and Container Escape
A critical vulnerability in the Linux kernel, known as “GhostLock” (CVE-2026-43499), has been disclosed by researchers at Nebula Security. This vulnerability, which has existed for 15 years, allows for reliable privilege escalation and container escape across nearly all Linux distributions. The issue dates back to Linux kernel version 2.6.39, released in 2011, and remained undetected…
-
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched.The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network…
-
Microsoft Introduces Execution Containers to Secure AI Agents on Windows
Microsoft has introduced a new security architecture to safeguard autonomous AI agents on Windows, unveiling the Microsoft Execution Containers (MXC) SDK at Build 2026. The move reflects a growing industry concern: as AI agents evolve from passive assistants into autonomous systems capable of executing code, accessing files, and orchestrating workflows, they introduce significant security and…
-
Apple Container: Open-source tool for Linux containers on the Mac
Developers on Apple silicon Macs have run Linux containers through software built around a single shared virtual machine for years. Apple’s open-source Container project … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/07/apple-container-open-source-linux-mac/
-
Microsoft wants to keep your AI agents from going rogue
Microsoft has introduced Microsoft Execution Containers (MXC), a cross-platform, policy-driven execution layer for AI agents on Windows and Windows Subsystem for Linux (WSL), … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/07/microsoft-execution-containers-ai-agents-constraints/
-
Aikido Buys Root for $70M to Automate Open-Source Patching
Deal Adds Hardened Packages, Automated CVE Fixes to Application Security Platform. Belgian software vendor Aikido Security acquired Boston-based Root for $70 million to embed automated vulnerability remediation into its application security platform, enabling enterprises to deploy hardened open-source packages and container images while reducing software supply-chain risk. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/aikido-buys-root-for-70m-to-automate-open-source-patching-a-32118
-
Veraltete Software in Container-Images Die unsichtbare Angriffsfläche in deutschen Cloud-Umgebungen
Container-Technologien sind in deutschen Unternehmen längst zum Standard geworden: Laut aktuellen Marktdaten nutzen 79 % aller Unternehmen Kubernetes für das Management ihrer Cloud-Anwendungen, und Gartner prognostiziert, dass bis 2027 mehr als 90 % der Unternehmen weltweit containerisierte Anwendungen in der Produktion betreiben werden. Gleichzeitig warnen 42 % der DevOps- und Sicherheitsfachleute, dass Sicherheit die größte…
-
WSL containers now build and run Linux workloads on Windows
Containers power a large share of cloud-native applications, AI workloads, and testing and deployment pipelines. Developers working on Windows have long pulled in third-party … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/30/microsoft-linux-wsl-containers/
-
FOSSBilling Flaw Lets Admin Attackers Abuse DI Container for SQL Access and RCE
A critical server-side template injection (SSTI) vulnerability in FOSSBilling, tracked as CVE-2026-28496, is exposing instances to potential full database compromise and remote code execution (RCE), with early signs of active exploitation appearing shortly after public disclosure. This flaw is documented under GitHub advisory GHSA-57mv-jm88-66jc and affects all versions up to 0.7.2. It has been patched…
-
Twistlock: Prisma Cloud Container Security Overview and Analysis for 2026
Prisma Cloud delivers container security, compliance, and runtime protection for cloud-native environments in 2026. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/products/twistlock/
-
CVE-2022-0492 wird aktiv ausgenutzt – Vier Jahre alte Linux-Kernel-Lücke erlaubt Container-Ausbruch
First seen on security-insider.de Jump to article: www.security-insider.de/linux-kernel-cve-2022-0492-container-ausbruch-cgroups-a-dfa9ed0a068ebd2d08d9dccbb4b05916/
-
DockSec: Open-source AI-powered Docker security scanner
DockSec is an OWASP Incubator Project that combines three container security scanners with a language-model layer for explanation and remediation. Created by Advait Patel, the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/08/docksec-open-source-ai-docker-security-scanner/
-
DockSec: Open-source AI-powered Docker security scanner
DockSec is an OWASP Incubator Project that combines three container security scanners with a language-model layer for explanation and remediation. Created by Advait Patel, the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/08/docksec-open-source-ai-docker-security-scanner/
-
Microsoft introduces execution containers for AI agents
First seen on scworld.com Jump to article: www.scworld.com/brief/microsoft-introduces-execution-containers-for-ai-agents
-
Attackers Exploit Docker, Kubernetes Misconfigs to Breach Hosts
Attackers are increasingly targeting Docker and Kubernetes environments by exploiting misconfigurations, weak isolation boundaries, and insecure APIs to compromise host systems and entire clusters. As containerization becomes the backbone of modern cloud infrastructure, threat actors are shifting focus from traditional endpoints to container ecosystems, where a single weakness can expose critical services at scale. A…
-
WhatsApp Chat Histories Exposed in Unencrypted Storage on macOS and iOS
Security researchers have raised concerns over how WhatsApp stores user chat data on macOS and iOS, revealing that message databases may be stored in unencrypted form within app group containers accessible by other applications from the same developer ecosystem. According to researchers at Mysk, WhatsApp stores chat histories in plaintext within a shared app group…
-
WhatsApp Chat Histories Exposed in Unencrypted Storage on macOS and iOS
Security researchers have raised concerns over how WhatsApp stores user chat data on macOS and iOS, revealing that message databases may be stored in unencrypted form within app group containers accessible by other applications from the same developer ecosystem. According to researchers at Mysk, WhatsApp stores chat histories in plaintext within a shared app group…
-
Edera and Minimus partner for endend container security
Tags: containerFirst seen on scworld.com Jump to article: www.scworld.com/brief/edera-and-minimus-partner-for-end-to-end-container-security
-
Developer workstations are the new beachhead
Tags: access, application-security, attack, authentication, cloud, container, control, credentials, edr, endpoint, exploit, github, group, Hardware, identity, incident response, infrastructure, malware, mfa, monitoring, network, software, supply-chain, threat, updateThe economics that drive the convergence: A typical developer workstation holds SSH keys, cloud provider credentials, container registry tokens, Git authentication tokens and CI/CD pipeline secrets. Many developers have administrative access to internal package registries and deployment infrastructure. Their machines often sit outside the hardened perimeter that security teams build around production systems.From an attacker’s…
-
Malicious Hugging Face model masquerading as OpenAI release hits 244K downloads
Part of a broader AI supply chain targeting: HiddenLayer, in its advisory, said that it identified six additional Hugging Face repositories uploaded under a separate account that used nearly identical loader logic and shared infrastructure with the campaign.The researchers also linked elements of the operation to earlier software supply-chain attacks involving npm typosquatting campaigns and…
-
PCPJack Worm Targets Docker, Kubernetes, Redis, and MongoDB Credentials
Tags: breach, cloud, container, credentials, cyber, data-breach, docker, extortion, framework, fraud, infrastructure, kubernetes, malware, spam, threat, wormA newly identified malware framework dubbed PCPJack is targeting exposed cloud and container infrastructure to steal credentials at scale while actively removing artifacts linked to the TeamPCP threat actor. Unlike typical cloud-focused campaigns, PCPJack skips cryptomining entirely and instead appears optimized for fraud, spam, extortion, and resale of stolen access. TeamPCP itself drew attention earlier in 2026…
-
PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems
Tags: cloud, container, credentials, cve, cybersecurity, data, data-breach, exploit, finance, framework, infrastructure, service, theft, wormCybersecurity researchers have disclosed details of a new credential theft framework dubbed PCPJack that targets exposed cloud infrastructure and ousts any artifacts linked to TeamPCP from the environments.”The toolset harvests credentials from cloud, container, developer, productivity, and financial services, then exfiltrates the data through attacker-controlled infrastructure while attempting First seen on thehackernews.com Jump to article:…
-
Financial stability risks are rising as AI fuels cyber-attacks, IMF warns; oil below $100 on Iran peace hopes as it happened
Rolling coverage of the latest economic and financial news<ul><li><a href=”https://www.theguardian.com/business/2026/may/07/climate-campaigners-attack-shell-over-windfall-profits-from-iran-war”>Climate campaigners attack Shell over ‘windfall’ profits from Iran war</li></ul>The Danish shipping giant <strong>Maersk</strong> has maintained its profit guidance for the year, even as it reported a spike in fuel costs and warned that traffic through the strait of Hormuz “remains at a near standstill”.The company,…
-
Financial stability risks are rising as AI fuels cyber-attacks, IMF warns; oil below $100 on Iran peace hopes business live
Rolling coverage of the latest economic and financial news<ul><li><a href=”https://www.theguardian.com/business/2026/may/07/climate-campaigners-attack-shell-over-windfall-profits-from-iran-war”>Climate campaigners attack Shell over ‘windfall’ profits from Iran war</li></ul>The Danish shipping giant <strong>Maersk</strong> has maintained its profit guidance for the year, even as it reported a spike in fuel costs and warned that traffic through the strait of Hormuz “remains at a near standstill”.The company,…

