CVE Tools

Containers on fire: from container escapes to supply chain attacks

Kaspersky SecurelistBy Alexander Chudnov18 min read

ResearchContainersTeamPCPDocker
Read at Kaspersky Securelist

Below is the opening; the full story is at Kaspersky Securelist.

From Kaspersky Securelist

Introduction

Modern infrastructures universally rely on containerization to deploy applications, scale services, and build cloud platforms. The use of Docker, Kubernetes, and similar technologies has become the corporate standard for efficient automation. However, as containers grow in popularity, so does the interest of malicious actors — a trend we actively track in our research into advanced cyberthreats. For instance, in one of its recent attacks, the APT group TeamPCP compromised Checkmarx KICS across multiple attack chains for different vectors. This included poisoning a Docker Hub repository to later steal Kubernetes secrets and other sensitive data. The tainted images distributed a stealer that was loaded during the KICS scanning process.…

Continue at Kaspersky Securelist

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store