Skip to content
How Did Aqua Catch a Cryptomining Attack Hiding in Memory?
Sign in
Contact
Support
We're hiring!
Platform
Aqua Platform
Runtime Powered Cloud Security
Monitor behavior, detect exploitable risk, enforce policy and contain threats across the application lifecycle.
Platform overview
Code Security
Scanning & Assurance
Scan artifacts across the entire software development lifecycle
Software Supply Chain Security
Protect your code, tools, and processes
Vulnerability Management
Advanced Code-to-Cloud vulnerability management to reduce noise and fix fast
Runtime Security
Container Security
Full lifecycle advanced protection for containerized applications
Cloud Workload Protection (CWPP)
Runtime protection for every cloud native workload
Hybrid-Cloud & Multi-Cloud Security
Code to Cloud security for hybrid and multi-cloud deployments
Posture Management
CI/CD Pipeline Security
Automate DevSecOps
Kubernetes Security
Holistic Kubernetes Security for the Enterprise
Cloud Security Posture Management
Extend traditional CSPM with workload visibility
Solutions
Use Cases
Automate DevSecOps
Security and speed without compromise
GenAI Application Security
Secure GenAI Applications from Code to Runtime
Detection and Response
Cloud native detection & Response (CNDR)
Hybrid-Cloud & Multi-Cloud
Security for hybrid and multi-cloud deployments
Prove Compliance
Controls for PCI, HIPAA, GDPR, and beyond
Solutions
Docker Security
Enterprise-Grade security for Docker environments
AWS Cloud Security
Protect cloud native workloads on AWS
Google Cloud Security
Secure K8s apps on Google Cloud Platform
OpenShift Security
Cloud Native Security for Red Hat OpenShift
VMware Tanzu Security
Native security across VMware Tanzu
Azure Cloud Security
Complete Security for Azure Container Workloads
Industry
Federal
CNAPP solution for Federal Government
Financial Services
One platform for financial services
Resources
The best of cloud native
Aqua Blog
Expert insight, best practices and advice on cloud native security, trends, threat intelligence and compliance
Read the Blog
Resources
Resources Center
eBooks, Data sheets, Whitepapers, Webinars, and much more
The Cloud Native Channel
Cloud native security webinars & videos
Aquademy
The Aqua academy
Cloud Native Wiki
The educational center for everything cloud native
Company
Recognized Leadership
CISO Choice Awards
Winner for Cloud Workload Protection Platform (CWPP)
Forrester Consulting: The Total Economic Impact™ of Aqua CNAPP
90% Reduction in vulnerability research and detection time
Frost & Sullivan CNAPP report
Top innovation leader
About Us
Newsroom
Customers
Partners
Careers
Support
Services
Upcoming Events
Connect
Contact
Twitter
Facebook
Linkedin
Instagram
News
Aqua Security Turns Runtime Intelligence into Action with Agentic Response, Debuts Risk Dashboards
Aqua Security Doubles Down on Runtime to Deliver Measurable Cloud Risk Reduction
ActiveState Joins Trivy Partner Connect to Cut CVE Noise and Reduce Alert Fatigue for Developers
Get Started
Aqua Cloud Native Blog
› Tags: Docker Security
Expert insight, best practices and advice on cloud native security, trends, threat intelligence and compliance.
CONTAINER SECURITY
A Security Review of Docker Official Images: Which Do You Trust?
A key element in building secure containerized applications is to ensure that the base image that you use is well-maintained and secure. A common piece of advice is to use the Docker Official Images for this purpose. However, our research reveals that you need to be careful when using these images, as some are no …
CONTAINER SECURITY
Top 22 Docker Security Best Practices: Ultimate Guide
While Docker has become synonymous with containers, various container tools and platforms have emerged to make the process of developing and running containers more efficient. Still, a lot of the same principles around Docker security apply for protecting container-based applications built with other tools as well. We compiled 20 essential Docker security best practices into …
CONTAINER SECURITY
The Challenges of Uniquely Identifying Your Images
One of the challenges of container security is ensuring that the image you’re getting is exactly what you expect it to be. Both from a security and consistency perspective, it’s important to ensure there are no surprises in what you’re downloading. Docker image tags, whilst convenient, can’t always be relied on to point to a …
SECURITY RESEARCH
Maneuver Docker API for Host Takeover
Threat Alert
Docker clients can communicate with the daemon either locally, via a unix socket, or over a network via a TCP socket. Aqua’s research team discovered an interesting attack vector running on top of an unsecured Docker socket API. Instead of running a malicious Docker image, the attacker changes the traditional entry-point to take control over …
SECURITY RESEARCH
CVE-2019-5021: Alpine Docker Image ‘null root password’ Vulnerability
A new vulnerability that impacts Alpine Docker images was published last week. The vulnerability is due to the ‘root’ user password which is set, by default, to NULL on Alpine Docker images from version 3.3 or higher.
SOFTWARE SUPPLY CHAIN SECURITY
Docker Hub Unauthorized Access Incident: What You Should Know
A few days ago, Docker discovered that a database holding the credentials of some 190,000 Docker Hub accounts was exposed to unauthorized access (about 5% of all Docker Hub accounts). We’ve been getting questions from customers on this, so I wanted to set the record straight on what we know and what we recommend doing.
SECURITY RESEARCH
Mitigating High Severity RunC Vulnerability (CVE-2019-5736)
Yesterday it was disclosed that a new high severity (CVSS score 7.2) vulnerability (CVE-2019-5736) was found in runc, that allows an attacker to potentially compromise the container host. Patches are already available from most providers (see below). Aqua customers can also prevent this vulnerability from being exploited by applying the appropriate runtime policies.
CONTAINER SECURITY
Popular Docker Networking and Kubernetes Networking Tools
In a previous post, we explored six tools for storing data for Docker containers. Another challenge in container environments is getting containers to network in a consistent and secure manner – especially as container workloads may appear on different hosts as applications scale out, then disappear when they’re not needed. On a single host, Docker …
CONTAINER SECURITY
10 Essential Container CI/CD Tools
Continuous integration and continuous delivery (CI/CD) are two of the biggest trends in software development. As companies move to release higher quality software at a faster pace, developers and engineers need new approaches to building, testing, and delivering products. As a result, many companies are turning to Docker to build, test, and deploy their applications.
SECURITY RESEARCH
Cryptocurrency Miners Abusing Containers: Anatomy of an (Attempted) Attack
This isn’t a story about a Docker vulnerability; it’s a story about how hackers are looking for unsecured Docker deployments where they can mine cryptocurrency. You shouldn’t leave your Docker daemon unsecured any more than you would leave your mail server unsecured. We’ve heard many accounts of attempted (sometimes successful) cryptocurrency mining attacks on container …
CONTAINER SECURITY
5 Essential Docker Storage Tools
Storage has been a hot topic for as long as containers have been around. According to a survey by Portworx, 26% of IT pros cite persistent storage as the most difficult challenge in adopting containers, and 44% blame inadequate tools as the main reason. Although containers are stateless by design, the need to store data …
KUBERNETES SECURITY
2017 in Review: Major Developments in the Container Ecosystem
From a “humble” $762 million in 2016, containers are predicted to grow faster than any other technology this year (as well as the next) and are on the way to become a $2.7B industry by 2020.
Page 1 of 2
1
2
Next ›
Need to secure enterprise workloads?
Aqua Cloud Native Application Protection Platform (CNAPP)
Go cloud native with the experts!
Get Demo