Docker Hub Unauthorized Access Incident: What You Should Know
ID: f7dc653f-9f51-5f62-a2f2-30566f06a43e
STIX ID: report--f7dc653f-9f51-5f62-a2f2-30566f06a43e
Feed Name: Aqua Security Blog
Docker disclosed unauthorized access to a database holding credentials for roughly 190,000 Docker Hub accounts (≈5%), exposing usernames, hashed passwords, and GitHub/Bitbucket autobuild tokens; affected tokens were revoked and affected users notified. The report recommends changing passwords and tokens, auditing logs and image history for tampering, and adopting stronger controls such as MFA, image encryption with keys in an external KMS, and improved DevOps security practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
