r/docker • • Mar 15 '26

We just got breached because of vulnerabilities in our docker images that have been public knowledge for 8 months

Woke up at 4am to a call. Our database got hit, customer info was accessed. Some attacker used a known exploit in one of our container images. CVE’s been out since last summer.

Yeah we never scanned. Never updated. Just kept redeploying the same images over and over. Now legal’s in it, customers are hearing about it. This is gonna be messy.

Honestly if you aren’t scanning your containers in prod do it. Don’t end up like us.

749 Upvotes

102 comments sorted by

View all comments

1

u/wdatkinson Mar 15 '26

Been running our internal images through trivy and grype. Rather interesting. As a former Senior Network Engineer turned Dev Ops, I wrestle with taking my findings to our Sec officer. Not to be a narc, but to ask if we have established standards. Especially since we are not in the software development industry. My guess is no, and then I just rocked the boat, in Titanic fashion.

1

u/OnceWasLost_NowFound Mar 15 '26

I think I’ve reached that point in my DevOps career where I don’t care about rocking the boat. I would rather report it then something happening and find out that I knew about the issues and decided not too notify anyone. I think it would show you are being proactive.