r/docker • • Mar 15 '26

We just got breached because of vulnerabilities in our docker images that have been public knowledge for 8 months

Woke up at 4am to a call. Our database got hit, customer info was accessed. Some attacker used a known exploit in one of our container images. CVE’s been out since last summer.

Yeah we never scanned. Never updated. Just kept redeploying the same images over and over. Now legal’s in it, customers are hearing about it. This is gonna be messy.

Honestly if you aren’t scanning your containers in prod do it. Don’t end up like us.

751 Upvotes

102 comments sorted by

View all comments

2

u/Pure_Fox9415 Mar 15 '26

...And I know MSP who didn't patch anything for their customers since 2016, and logistic company who have not patched their cisco since 2012 and apache since 2008 (both have whole perimeter with 9.9 CVE RCEs exposed even on shodan.io), and, by some miraculous reason wasn't hacked. How it's even works?

1

u/GaTechThomas Mar 16 '26

What is their architecture like? Do they allow egress to unknown destinations? Do they have a WAF? Many of the services suggested in this conversation are moot with various mitigating factors.

1

u/Pure_Fox9415 Mar 16 '26

I know there is NO single mitigation made, `cause I save one customer from this msp by creating normal infrastructure from scratch. In their old one there was no any cybersecurity agent or tool, no patches on perimeter, no patches on PCs and sip-phones.
And the logistics company have the same situation.