Tag: docker
-
DockerSpy: Search for images on Docker Hub, extract sensitive information
DockerSpy scans Docker Hub for images and retrieves sensitive information, including authentication secrets, private keys, and other confidential data… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/09/11/dockerspy-extract-sensitive-information-docker-hub-images/
-
Docker-OSX image used for security research hit by Apple DMCA takedown
The popular Docker-OSX project has been removed from Docker Hub after Apple filed a DMCA (Digital Millennium Copyright Act) takedown request, alleging… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/docker-osx-image-used-for-security-research-hit-by-apple-dmca-takedown/
-
You should probably fix this 5-year-old critical Docker vuln fairly sharpish
Tags: dockerFirst seen on theregister.com Jump to article: www.theregister.com/2024/07/25/5yo_docker_vulnerability/
-
Alte Sicherheitslücke zur Rechteausweitung wieder aufgetaucht
Eine Schwachstelle in den Autorisierung-Plug-ins hatte Docker 2019 geschlossen. Sie ist aber kurz danach als Regression wieder in die Engine eingeflos… First seen on heise.de Jump to article: www.heise.de/news/Docker-Alte-Sicherheitsluecke-zur-Rechteausweitung-wieder-aufgetaucht-9811582.html
-
Container angreifbar: Docker muss kritische Schwachstelle von 2019 erneut patchen
Docker hatte die Lücke längst geschlossen. Nur Monate später flog der Patch aber wieder raus. Die Docker Engine ist damit fünf Jahre lang angreifbar g… First seen on golem.de Jump to article: www.golem.de/news/container-angreifbar-docker-muss-kritische-schwachstelle-von-2019-erneut-patchen-2407-187423.html
-
Critical Docker Engine Flaw Allows Attackers to Bypass Authorization Plugins
Docker is warning of a critical flaw impacting certain versions of Docker Engine that could allow an attacker to sidestep authorization plugins (AuthZ… First seen on thehackernews.com Jump to article: thehackernews.com/2024/07/critical-docker-engine-flaw-allows.html
-
Docker fixes critical auth bypass flaw, again (CVE-2024-41110)
A critical-severity Docker Engine vulnerability (CVE-2024-41110) may be exploited by attackers to bypass authorization plugins (AuthZ) via specially c… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/07/25/cve-2024-41110/
-
Critical bug in Docker Engine allowed attackers to bypass authorization plugins
A critical flaw in some versions of Docker Engine can be exploited to bypass authorization plugins (AuthZ) under specific circumstances. A vulnerabili… First seen on securityaffairs.com Jump to article: securityaffairs.com/166160/hacking/docker-engine-critical-flaw.html
-
Docker fixes critical 5-year old authentication bypass flaw
Docker has issued security updates to address a critical vulnerability impacting certain versions of Docker Engine that could allow an attacker to byp… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/docker-fixes-critical-5-year-old-authentication-bypass-flaw/
-
Docker Patches Critical AuthZ Plugin Bypass Vulnerability Dating Back to 2018
The vulnerability, tagged as CVE-2024-41110 with a CVSS severity score of 10/10, was originally found and fixed in 2018. The post Docker Patches Criti… First seen on securityweek.com Jump to article: www.securityweek.com/docker-patches-critical-authz-plugin-bypass-vulnerability-dating-back-to-2018/
-
Portainer: Open-source Docker and Kubernetes management
Portainer Community Edition is an open-source, lightweight service delivery platform for containerized applications. It enables the management of Dock… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/07/01/portainer-open-source-docker-kubernetes-management/
-
New Malware Targets Exposed Docker APIs for Cryptocurrency Mining
Cybersecurity researchers have uncovered a new malware campaign that targets publicly exposed Docket API endpoints with the aim of delivering cryptocu… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/new-malware-targets-exposed-docker-apis.html
-
Novel malware campaign sets sights on misconfigured Docker APIs
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/novel-malware-campaign-sets-sights-on-misconfigured-docker-apis
-
Cryptojacking campaign targets exposed Docker APIs
A malware campaign targets publicly exposed Docker API endpoints to deliver cryptocurrency miners and other payloads. Researchers at Datadog uncovered… First seen on securityaffairs.com Jump to article: securityaffairs.com/164668/cyber-crime/malware-campaign-docker-api-endpoints.html
-
Commando Cat Docker Cryptojacking: Alert Prevention Tips
Recent reports have unveiled a concerning cyber threat orchestrated by a group identified as Commando Cat. This threat actor has been actively engagin… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/commando-cat-docker-cryptojacking-alert-prevention-tips/
-
Hackers Employing New Techniques To Attack Docker API
Attackers behind Spinning YARN launched a new cryptojacking campaign targeting publicly exposed Docker Engine hosts by using new binaries chkstart (re… First seen on gbhackers.com Jump to article: gbhackers.com/new-hacking-techniques-docker-api/
-
Commando Cat Cryptojacking Attacks Target Misconfigured Docker Instances
The threat actor known as Commando Cat has been linked to an ongoing cryptojacking attack campaign that leverages poorly secured Docker instances to d… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/commando-cat-cryptojacking-attacks.html
-
‘Commando Cat’ Digs Its Claws into Exposed Docker Containers
First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/-commando-cat-digs-its-claws-into-exposed-docker-containers
-
Unsecured Docker servers subjected to ongoing cryptojacking campaign
Tags: dockerFirst seen on scmagazine.com Jump to article: www.scmagazine.com/brief/unsecured-docker-servers-subjected-to-ongoing-cryptojacking-campaign
-
Drei Fragen und Antworten: Warum sind Repositories so beliebt bei Angriffen?
In den letzten Wochen wurden viele Angriffe auf Software-Repositories bekannt: XZ, Python oder zuletzt Docker Hub. Repos scheinen es Hackern leichtzum… First seen on heise.de Jump to article: www.heise.de/news/Drei-Fragen-und-Antworten-Warum-sind-Repositories-so-beliebt-bei-Angriffen-9716252.html
-
Angriffe auf Docker-Hub 3 Millionen Repositories kompromittiert
Aktuelle Untersuchungen des Forschungsteams von JFrog haben bedeutende Sicherheitsmängel auf Docker-Hub aufgedeckt, der weltweit führenden Plattform, … First seen on netzpalaver.de Jump to article: netzpalaver.de/2024/05/03/angriffe-auf-docker-hub-3-millionen-repositories-kompromittiert/
-
JFrog entdeckt Malware auf Docker Hub – Millionen Repositories sind mit bösartigen Metadaten kompromittiert
First seen on security-insider.de Jump to article: www.security-insider.de/malware-angriffe-docker-hub-neue-erkenntnisse-a-058b4e928e829231d5a8ef9cb93b18ba/
-
Millions of Malicious ‘Imageless’ Containers Planted on Docker Hub Over 5 Years
Cybersecurity researchers have discovered multiple campaigns targeting Docker Hub by planting millions of malicious imageless containers over the past… First seen on thehackernews.com Jump to article: thehackernews.com/2024/04/millions-of-malicious-imageless.html
-
Angriffe auf Docker-Hub 3 Millionen Repositories kompromittiert
Aktuelle Untersuchungen des Forschungsteams von JFrog haben bedeutende Sicherheitsmängel auf Docker-Hub aufgedeckt, der weltweit führenden Plattform, … First seen on netzpalaver.de Jump to article: netzpalaver.de/2024/05/03/angriffe-auf-docker-hub-3-millionen-repositories-kompromittiert/
-
JFrog entdeckt Angriffe auf Docker Hub 3 Millionen Repositories kompromittiert
Da Docker Hub weiterhin eine entscheidende Rolle im Entwickler-Ökosystem spielt, müssen die Sicherheitspraktiken weiterentwickelt werden, um diese Sch… First seen on infopoint-security.de Jump to article: www.infopoint-security.de/jfrog-entdeckt-angriffe-auf-docker-hub-3-millionen-repositories-kompromittiert/a37280/
-
Attackers Planted Millions of Imageless Repositories on Docker Hub
Tags: dockerFirst seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/attackers-planted-millions-of-imageless-repositories-on-docker-hub
-
Millions of Malicious Containers Found on Docker Hub
First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/malicious-containers-found-docker/
-
2,8 Millionen Docker-Hub-Repositories mit Malware oder Phishing verseucht
First seen on heise.de Jump to article: www.heise.de/news/2-8-Millionen-Docker-Hub-Repositories-mit-Malware-oder-Phishing-verseucht-9705402.html
-
Malicious repositories proliferate in Docker Hub
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/malicious-repositories-proliferate-in-docker-hub
-
Millions of Malicious >>Imageless<< Docker Hub Repositories Drop Malware
In a startling revelation, nearly 20% of Docker Hub repositories have been identified as conduits for malware and phishing scams, underscoring the sop… First seen on gbhackers.com Jump to article: gbhackers.com/millions-of-malicious-imageless-docker-hub-repositories/

