malware Archives - Cloud Native Now Mon, 23 Dec 2024 13:50:31 +0000 en-US hourly 1 https://wordpress.org/?v=6.7.1 https://cloudnativenow.com/wp-content/uploads/2023/04/cropped-CCn-bug--32x32.png malware Archives - Cloud Native Now 32 32 94898820 Best of 2024: JFrog Reveals Docker Hub Compromise Spanning Millions of Repositories https://cloudnativenow.com/editorial-calendar/best-of-2024/best-of-2024-jfrog-reveals-docker-hub-compromise-spanning-millions-of-repositories/?utm_source=rss&utm_medium=rss&utm_campaign=best-of-2024-jfrog-reveals-docker-hub-compromise-spanning-millions-of-repositories Mon, 23 Dec 2024 13:50:30 +0000 https://cloudnativenow.com/?p=160113 Docker Hub, container images, Ensuring Container Security

Docker Hub, container images, Ensuring Container Security

Malware attacks against millions of Docker Hub repositories have been underway since 2021. Assume all the content you host on a publicly accessible repository might be compromised.

The post Best of 2024: JFrog Reveals Docker Hub Compromise Spanning Millions of Repositories appeared first on Cloud Native Now.

]]>
160113
JFrog Reveals Docker Hub Compromise Spanning Millions of Repositories https://cloudnativenow.com/topics/cloudnativedevelopment/docker/jfrog-reveals-docker-hub-compromise-spanning-millions-of-repositories/?utm_source=rss&utm_medium=rss&utm_campaign=jfrog-reveals-docker-hub-compromise-spanning-millions-of-repositories Tue, 30 Apr 2024 13:00:53 +0000 https://cloudnativenow.com/?p=158818 Docker Hub, container images, Ensuring Container Security

Docker Hub, container images, Ensuring Container Security

Malware attacks against millions of Docker Hub repositories have been underway since 2021. Assume all the content you host on a publicly accessible repository might be compromised.

The post JFrog Reveals Docker Hub Compromise Spanning Millions of Repositories appeared first on Cloud Native Now.

]]>
158818
Cado Security Labs Exposes Commando Cat Container Malware Campaign https://cloudnativenow.com/features/cado-security-labs-exposes-commando-cat-container-malware-campaign/?utm_source=rss&utm_medium=rss&utm_campaign=cado-security-labs-exposes-commando-cat-container-malware-campaign Thu, 01 Feb 2024 16:55:13 +0000 https://cloudnativenow.com/?p=158266 Cado Trend Micro Docker vulnerability

Cado Trend Micro Docker vulnerability

Cado Security Labs today disclosed it has discovered a malware campaign, dubbed “Commando Cat,” that targets Docker API endpoints.

The post Cado Security Labs Exposes Commando Cat Container Malware Campaign appeared first on Cloud Native Now.

]]>
158266
Cado Security Labs Identifies Campaign to Compromise Docker Hosts https://cloudnativenow.com/features/cado-security-labs-identifies-campaign-to-compromise-docker-hosts/?utm_source=rss&utm_medium=rss&utm_campaign=cado-security-labs-identifies-campaign-to-compromise-docker-hosts Thu, 18 Jan 2024 12:57:51 +0000 https://cloudnativenow.com/?p=158127 Cado VMware container security

Cado VMware container security

Cado Security identified an ongoing effort to abuse Docker containers using a 9hits service to create fraudulent web traffic.

The post Cado Security Labs Identifies Campaign to Compromise Docker Hosts appeared first on Cloud Native Now.

]]>
158127
Deepfence Expands Scope of Open Source Container Security Platform https://cloudnativenow.com/features/deepfence-expands-scope-of-open-source-container-security-platform/?utm_source=rss&utm_medium=rss&utm_campaign=deepfence-expands-scope-of-open-source-container-security-platform Wed, 10 Aug 2022 18:15:00 +0000 https://cloudnativenow.com/?p=153217 Deepfence cloud-native SQL Server security Kubernetes

Deepfence cloud-native SQL Server security Kubernetes

Deepfence today announced it has updated its open source ThreatMapper project to add expanded visualizations of attack paths and a scanner based on the YARA tool many security researchers use to identify and classify malware samples. In addition, version 4.1 of ThreatMapper now includes enterprise-grade cloud security posture management (CSPM)

The post Deepfence Expands Scope of Open Source Container Security Platform appeared first on Cloud Native Now.

]]>
153217
Lacework Labs Finds Backdoors in Container Images https://cloudnativenow.com/features/lacework-labs-finds-backdoors-in-container-images/?utm_source=rss&utm_medium=rss&utm_campaign=lacework-labs-finds-backdoors-in-container-images Fri, 03 Sep 2021 18:38:42 +0000 https://cloudnativenow.com/?p=15403 Lacework Red Hat Aqua Security

Lacework Red Hat Aqua Security

Cloud security platform provider Lacework this week published a report that reveals cybercriminals are now creating backdoors in legitimate container images. Lacework Labs reports it has discovered that a threat actor, dubbed TeamTNT, has been creating backdoors in Docker images that went undetected by the IT teams that deployed those

The post Lacework Labs Finds Backdoors in Container Images appeared first on Cloud Native Now.

]]>
15403
Report: Docker Hub Container Vulnerabilities High https://cloudnativenow.com/topics/cloudnativesecurity/report-docker-hub-container-vulnerabilities-high/?utm_source=rss&utm_medium=rss&utm_campaign=report-docker-hub-container-vulnerabilities-high Thu, 03 Dec 2020 14:55:16 +0000 https://cloudnativenow.com/?p=13626 container vulnerabilities

container vulnerabilities

Prevasio, a provider of a cloud service for scanning container images, this week released a report based on a scan of 4 million public container images found in Docker Hub that concludes just over half the images (51%) were rife with critical vulnerabilities. Only 13% of container scans resulted in

The post Report: Docker Hub Container Vulnerabilities High appeared first on Cloud Native Now.

]]>
13626
Protecting Containers Against ‘Doki’ Malware https://cloudnativenow.com/topics/cloudnativesecurity/protecting-containers-against-doki-malware/?utm_source=rss&utm_medium=rss&utm_campaign=protecting-containers-against-doki-malware Mon, 24 Aug 2020 07:00:13 +0000 https://cloudnativenow.com/?p=12822 container vulnerabilities

container vulnerabilities

Security researchers at Intezer recently alerted the enterprise security community about Doki, a new and substantial malware targeting public Docker environments. Downloaded and installed via a Linux backdoor, Doki uses Dyn’s DynDNS service and a unique Domain Generation Algorithm (DGA) based on the Dogecoin cryptocurrency blockchain to locate its controller

The post Protecting Containers Against ‘Doki’ Malware appeared first on Cloud Native Now.

]]>
12822
Docker Hub Distributing Cryptomining Malware? https://cloudnativenow.com/topics/cloudnativesecurity/docker-hub-distributing-cryptomining-malware/?utm_source=rss&utm_medium=rss&utm_campaign=docker-hub-distributing-cryptomining-malware Fri, 26 Jun 2020 06:00:05 +0000 https://cloudnativenow.com/?p=12388 cryptojacking Docker Hub

cryptojacking Docker Hub

A pair of cybersecurity reports published this week suggests the level of cryptomining malware lurking in the Docker Hub repository is potentially greater than most IT teams realize. Aqua Security, a provider of tools for scanning container images, reports it has discovered no fewer than 23 container images stored in

The post Docker Hub Distributing Cryptomining Malware? appeared first on Cloud Native Now.

]]>
12388
RunC Bug Highlights Docker Security Challenges, But It’s Not Fatal https://cloudnativenow.com/features/runc-bug-highlights-docker-security-challenges-not-fatal/?utm_source=rss&utm_medium=rss&utm_campaign=runc-bug-highlights-docker-security-challenges-not-fatal Fri, 20 Jan 2017 07:00:25 +0000 https://cloudnativenow.com/?p=2349

It’s a Docker admin’s worst nightmare: An attacker compromises a container, then uses it to gain control of the entire host server. A newly discovered security vulnerability in runC enables just that type of attack—at least in theory. The vulnerability, CVE-2016-9962, allows a process running inside a container to discover

The post RunC Bug Highlights Docker Security Challenges, But It’s Not Fatal appeared first on Cloud Native Now.

]]>
2349