#docker


Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Sep 28, 2026 // 14:50

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that’s targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent […]

New Carbonato malware uses AI agents to hijack exposed Docker hosts

Sep 24, 2026 // 23:37

A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. The malware features […]

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Sep 17, 2026 // 18:51

Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere […]

Hackers exploit critical auth bypass in Gitea Docker image

Jul 10, 2026 // 18:56

Hackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to impersonate any user, […]

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

Jul 6, 2026 // 19:29

Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The vulnerability in question […]

Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain

Apr 22, 2026 // 21:00

Cybersecurity researchers have warned of malicious images pushed to the official “checkmarx/kics” Docker Hub repository. In an alert published today, software supply chain security company […]

Docker Flaw (CVE-2026-34040): Authorization Bypass Leads to Host Control.

Apr 7, 2026 // 18:18

A critical flaw has been found in Docker Engine, potentially enabling attackers to bypass security authorization plugins (AuthZ) in certain situations. Identified as CVE-2026-34040 (CVSS […]

Trivy Supply Chain Attack: Docker, GitHub Impacted. OR Trivy Hacked: Docker & GitHub Supply Chain Affected.

Mar 24, 2026 // 10:58

The TeamPCP hackers, responsible for the Trivy supply-chain attack, kept targeting Aqua Security by uploading harmful Docker images and taking control of the GitHub organization […]

Trivy Hack: Docker Infostealer, Worm, & Kubernetes Wiper Deployed

Mar 23, 2026 // 11:33

Following the Trivy supply chain attack, security experts have detected harmful components spread via Docker Hub, indicating a widespread impact on development environments. The last […]