< ciso
brief />
Tag Banner

All news with #docker tag

25 articles

Carbonato botnet exploits exposed Docker daemons

๐Ÿ” Cybersecurity researchers disclosed a new botnet named Carbonato that targets unauthenticated Docker daemons to deploy the open-source Hermes Agent AI framework. The malware installs the agent, overwrites its SOUL.md persona to accept Telegram commands, and uses privileged containers, reverse SSH tunnels, cron jobs and watchdogs to maintain persistence and propagate. ThreatDown traced artifacts to an exposed Docker registry and found the campaign includes other malicious operations such as trojanized crypto wallets.
read more โ†’

Carbonato malware hijacks exposed Docker hosts

๐Ÿ›ก๏ธ A new botnet named Carbonato targets unsecured Docker daemons to install the Hermes Agent AI framework and seize control. Researchers from Malwarebytes ThreatDown found evidence from October 2024 to August 2026 showing worm-like spreading via unauthenticated Docker APIs on port 2375. The malware launches privileged containers, opens reverse SSH tunnels, installs operator keys, and establishes persistence mechanisms while reporting deployments over Telegram.
read more โ†’

Critical Docker Sandboxes Escape Flaw Fixed in 0.42.0

๐Ÿ›ก๏ธ Docker warned on September 15 that a critical flaw, CVE-2026-77179, in Docker Sandboxes for macOS allowed code running inside a VM to escape the shared project directory and read or modify files on the host as the VMM user; the issue was fixed in 0.42.0 released September 7. A second high-severity issue, CVE-2026-79994, let guests trick a relay into connecting to AF_UNIX sockets outside the workspace. Docker recommends upgrading to 0.42.0+ or using clone mode and avoiding read-write host mounts until patched.
read more โ†’

Critical Gitea Docker auth bypass actively exploited

๐Ÿ”’ A critical authentication bypass (CVE-2026-20896) in the official Gitea Docker image is being actively exploited to impersonate any user, including administrators, when reverse-proxy authentication headers like X-WEBAUTH-USER are trusted from all sources. Sysdig reported the first in-the-wild exploitation roughly two weeks before public disclosure, and around 6,200 Gitea instances are internet-exposed. Gitea released versions 1.26.3 and 1.26.4 to address the issue and advises immediate upgrades or restricting REVERSE_PROXY_TRUSTED_PROXIES to known IPs.
read more โ†’

Threat actors scan for Gitea Docker authentication flaw

๐Ÿ” Security researchers report that threat actors have started probing a critical Gitea Docker image vulnerability, CVE-2026-20896 (CVSS 9.8). The flaw arises because the official Docker image sets REVERSE_PROXY_TRUSTED_PROXIES = * by default, allowing unauthenticated clients to send an X-WEBAUTH-USER header and gain elevated access when reverse-proxy authentication is enabled. Gitea patched the issue in version 1.26.3 by removing the wildcard and making reverse-proxy authentication opt-in, and Sysdig observed initial exploitation attempts shortly after disclosure.
read more โ†’

Chainguard launches Athena coalition to protect OSS

๐Ÿ”’ Chainguard has launched Athena, an industry coalition announced on June 16 to protect open-source software from attacks facilitated by frontier AI models. Founding members include BNY, Cisco, Cloudflare, Docker, JPMorganChase, PwC and others. Athena pools vulnerability findings into a shared platform, applies private patches and provides mitigations to members before public disclosure. The initiative aims to coordinate upstream fixes and partner with the Linux Foundation for broader incident response support.
read more โ†’

AWS Transform Adds Automated Containerization for Migrations

๐Ÿ“ฆ AWS Transform now automates replatforming to containers during migrations, extending its agentic AI to generate Dockerfiles, build images, and publish to Amazon ECR. It supports repositories from GitHub, Bitbucket, GitLab, or .zip sources and builds deployment artifacts for Amazon ECS and Amazon EKS. Integrated security scanning and Terraform and Helm outputs simplify operations. Available in all Regions where AWS Transform is offered.
read more โ†’

PCPJack Campaign Removes TeamPCP Artifacts from Cloud

๐Ÿ”’ Security researchers uncovered PCPJack, a credentialโ€‘theft framework that targets exposed cloud infrastructure and removes artifacts tied to TeamPCP. SentinelOne reports PCPJack worms through services to harvest credentials from Docker, Kubernetes, Redis, MongoDB, RayML and vulnerable web apps. Unlike many cloud campaigns it omits cryptoโ€‘mining and actively removes TeamPCP miner code, indicating monetization through credential theft, resale, fraud or extortion.
read more โ†’

Old Docker AuthZ Bypass Reappears, Patch Released Now

โš ๏ธResearchers from Cyera disclosed a high-severity authorization bypass in Docker Engine (CVE-2026-34040) that allows attackers with Docker API access to evade third-party AuthZ plug-ins and execute privileged commands on hosts. The flaw, rated 8.8 on the CVSS scale, was fixed in Docker Engine 29.3.1 and Docker Desktop 4.66.1. As an interim mitigation, administrators can filter malicious requests by limiting API request size (for example, blocking requests over 512KB) until patches are deployed.
read more โ†’

Docker CVE-2026-34040 Lets Attackers Bypass AuthZ Exploit

โš  A high-severity flaw (CVE-2026-34040, CVSS 8.8) in Docker Engine can allow an attacker with API access to bypass AuthZ plugins by causing the daemon to forward requests without their body. The bug is tied to an incomplete fix for CVE-2024-41110 and arises when oversized, padded HTTP requests are dropped before reaching the authorization plugin. An attacker who pads a container-creation request above the threshold can cause the daemon to create a privileged container that mounts the host filesystem. Docker Engine 29.3.1 contains the patch; mitigations include avoiding body-dependent AuthZ plugins, restricting API access to trusted users, or running Docker in rootless mode.
read more โ†’

Trivy supply-chain breach escalates into Lapsus$ extortion

๐Ÿ” A supply-chain compromise of Trivy has escalated into an extortion campaign linked to Lapsus$, with Mandiant reporting over 1,000 impacted enterprise SaaS environments and the potential for many more. Initial access by cloud-native actor TeamPCP led to stolen credentials that were used to backdoor packages and extend control to projects such as LiteLLM. Security firms Wiz and Socket describe malicious Docker and npm artifacts, a self-replicating worm, and manipulated CI/CD tags, while Aqua Security and partners work to rotate credentials and contain the incident.
read more โ†’

Trivy supply-chain breach spreads infostealer via Docker

๐Ÿšจ Researchers uncovered trojanized Trivy images on Docker Hub after a supply-chain compromise that pushed malicious releases to developer environments. The last known clean release is 0.69.3; tags 0.69.4โ€“0.69.6 were removed after analysis linked several images to the TeamPCP infostealer. The incident also affected related GitHub Actions and spawned downstream npm compromises and repository defacements.
read more โ†’

Docker patches critical Ask Gordon AI 'DockerDash' flaw

๐Ÿ›ก๏ธ Researchers disclosed a critical prompt-injection flaw, codenamed DockerDash, that allowed malicious Docker image metadata to hijack the Ask Gordon AI assistant in Docker Desktop and the Docker CLI. The vulnerability, discovered by Noma Labs, could enable remote code execution or sensitive data exfiltration by treating unverified LABEL fields as executable instructions. Docker fixed the issue in Ask Gordon version 4.50.0 (November 2025). Administrators should upgrade and apply zero-trust validation to AI toolchains and MCP/Gateway integrations.
read more โ†’

DockerDash: Metadata Flaw in Docker's Ask Gordon AI

โš ๏ธ Noma Labs disclosed a critical vulnerability, dubbed DockerDash, in Docker's Ask Gordon AI assistant that allows unverified image metadata to be treated as executable instructions. The flaw exploits a trust failure in the Model Context Protocol (MCP) gateway: Ask Gordon reads Docker LABEL metadata, forwards the interpreted content to MCP, and MCP tools execute it without validation. Depending on deployment this can enable remote code execution (cloud/CLI) or large-scale data exfiltration and reconnaissance in Docker Desktop. Docker issued mitigations in Docker Desktop 4.50.0 and users are urged to upgrade.
read more โ†’

Docker Makes 1,000 Hardened Container Images Open Source

๐Ÿณ Docker has open-sourced and made freely available over 1,000 Docker Hardened Images (DHI) under the Apache 2.0 license to provide a secure, minimal foundation for containerized applications. The images are rootless, stripped of unnecessary components, SBOM-verifiable, and shipped with SLSA Build Level 3 provenance and proof of authenticity. Docker will continue to publish fixes for DHI components while reserving a 7-day critical CVE patching SLA for the commercial DHI Enterprise tier. The full DHI catalog and subscription options are available from Docker's product offerings.
read more โ†’

Over 10,000 Docker Hub Images Expose Live Secrets Globally

๐Ÿ”’ A November scan by threat intelligence firm Flare found 10,456 Docker Hub images exposing credentials, including live API tokens for AI models and production systems. The leaks span about 101 organizations โ€” from SMBs to a Fortune 500 company and a major national bank โ€” and often stem from mistakes like committed .env files, hardcoded tokens, and Docker manifests. Flare urges immediate revocation of exposed keys, centralized secrets management, and active SDLC scanning to prevent prolonged abuse.
read more โ†’

Critical runC Vulnerabilities Allow Docker Container Escape

โš ๏ธ Three newly disclosed vulnerabilities in runC (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) could allow attackers to bypass container isolation and obtain root write access on the host. The issues involve manipulated bind mounts and redirected writes to /proc, and one flaw affects runC releases back to 1.0.0-rc3. Patches are available in recent runC releases; administrators should update, monitor for suspicious symlink/mount activity, and consider enabling user namespaces or running rootless containers as mitigations.
read more โ†’

Docker offers Hardened Images for SMBs and startups

๐Ÿ”’ Docker has opened unlimited, subscription-based access to its Hardened Images catalog starting today, offering a 30-day free trial to make near-zero CVE container images affordable for startups and SMBs. These images are built from source, signed, rootless by default, include SBOM and VEX data, and are covered by a seven-day patch SLA for newly discovered CVEs. Docker says removing nonessential components can reduce attack surface by up to 95%, and hardened variants are compatible with Alpine and Debian and can be adopted by changing a single Dockerfile line.
read more โ†’

ShadowV2 Turns Misconfigured Docker into DDoS Service

๐Ÿ›ก๏ธ Darktrace researchers uncovered a ShadowV2 campaign that leverages exposed Docker APIs on AWS EC2 to provision containers and run a Go-based remote access trojan, converting misconfigured cloud containers into distributed DDoS nodes. The attackers create containers on victim hosts rather than importing malicious images, likely to reduce forensic traces, and use the Python Docker SDK to interact with exposed daemons. ShadowV2 operators employ advanced techniques including HTTP/2 rapid reset and Cloudflare evasion, and the platform includes APIs, a Tailwind/FastAPI UI and operator logins that turn botnet control into a commercialized DDoS-as-a-Service offering.
read more โ†’

ShadowV2 Botnet Highlights Growth of DDoS-as-a-Service

๐Ÿ›ก๏ธ Darktrace has uncovered a ShadowV2 campaign that combines a GitHub CodeSpaces-hosted Python command-and-control framework, a Docker-based spreader, and a Go-based RAT to operate a DDoS-as-a-service platform. Attackers target exposed Docker daemons on AWS EC2 to build on-victim images and deploy malware via environment variables, reducing forensic artifacts. The platform exposes an OpenAPI-driven UI and multi-tenant API enabling HTTP/HTTP2 floods, UAM bypasses, and other configurable attack options.
read more โ†’