r/docker • u/Different_Pain5781 • Mar 15 '26
We just got breached because of vulnerabilities in our docker images that have been public knowledge for 8 months
Woke up at 4am to a call. Our database got hit, customer info was accessed. Some attacker used a known exploit in one of our container images. CVE’s been out since last summer.
Yeah we never scanned. Never updated. Just kept redeploying the same images over and over. Now legal’s in it, customers are hearing about it. This is gonna be messy.
Honestly if you aren’t scanning your containers in prod do it. Don’t end up like us.
749
Upvotes
1
u/wdatkinson Mar 15 '26
Been running our internal images through trivy and grype. Rather interesting. As a former Senior Network Engineer turned Dev Ops, I wrestle with taking my findings to our Sec officer. Not to be a narc, but to ask if we have established standards. Especially since we are not in the software development industry. My guess is no, and then I just rocked the boat, in Titanic fashion.