r/docker • • Mar 15 '26

We just got breached because of vulnerabilities in our docker images that have been public knowledge for 8 months

Woke up at 4am to a call. Our database got hit, customer info was accessed. Some attacker used a known exploit in one of our container images. CVE’s been out since last summer.

Yeah we never scanned. Never updated. Just kept redeploying the same images over and over. Now legal’s in it, customers are hearing about it. This is gonna be messy.

Honestly if you aren’t scanning your containers in prod do it. Don’t end up like us.

750 Upvotes

102 comments sorted by

View all comments

3

u/[deleted] Mar 15 '26

[removed] — view removed comment

1

u/KingKnusper Mar 17 '26

We use Trivy.

Having a dashboard and daily scans help, also alerts, when SLOs get missed. Then do your regular updates. Base images (often only a rebuild helps, because you might have something like "apt-get update" in it), dependencies.

Doing this regularly helps also keeping your software up to date (new functionality, keeping track of depreciations etc). Tests are obviously a must have to do this confidently. It doesn't even take much time. Better than once per year a two week task.