Over 10,000 Docker Hub images found leaking credentials, auth keys
ID: 69b18b38-63b8-5388-ac30-1c4ac31e520d
STIX ID: report--69b18b38-63b8-5388-ac30-1c4ac31e520d
Feed Name: Bleeping Computer
Researchers found 10,456 Docker Hub images exposing secrets — including thousands of AI model keys and credentials impacting about 101 companies (from SMBs to a Fortune 500 firm and a major bank). Leaks stem from hardcoded tokens, .env files, image manifests and shadow‑IT accounts; many exposed keys were not revoked, enabling potential access to cloud environments, CI/CD pipelines, repositories and payment systems. The report recommends removing secrets from images, using secrets managers, scanning the SDLC, and revoking exposed credentials immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
