Remove docker-security
article thumbnail

TeamTNT is back and targets servers to run Bitcoin encryption solvers

Security Affairs

The TeamTNT botnet is a crypto-mining malware operation that has been active since April 2020 and targets Docker installs. The activity of the TeamTNT group has been detailed by security firm Trend Micro, but in August 2020 experts from Cado Security discovered that botnet is also able to target misconfigured Kubernetes installations.

article thumbnail

How to create a Docker secret and use it to deploy a service

Tech Republic Security

Docker secrets are a way to encrypt things like passwords and certificates within a service and container. Jack Wallen shows you the basics of creating and using this security-centric tool. The post How to create a Docker secret and use it to deploy a service appeared first on TechRepublic.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Thousands of secrets lurk in app images on Docker Hub

Security Affairs

Thousands of secrets have been left exposed on Docker Hub, a platform where web developers collaborate on their code for web applications. The Docker Hub store has at least 5,493 container images that contain secrets and could be considered as exposing sensitive information. What were the web apps leaking?

article thumbnail

Threat Group TeamTNT Returns with New Cloud Attacks

eSecurity Planet

A retired threat actor has returned with new attacks aimed at the cloud, containers – and encryption keys. These operations specifically target Docker instances and APIs. Also read: Top Container Security Solutions. All internet communications, including SSL and SSH, rely on private and public keys for encryption.

article thumbnail

How to set up secure credential storage for Docker

Tech Republic Security

Learn how to avoid saving your Docker login credentials in plain text by creating an encrypted credential storage.

article thumbnail

How to set up secure credential storage for Docker

Tech Republic Security

Learn how to avoid saving your Docker login credentials in plain text by creating an encrypted credential storage.

article thumbnail

'Darcula' Phishing Service Unleashes Sophisticated Smishing Attacks

SecureWorld News

A new Phishing-as-a-Service (PhaaS) threat called "darcula" is taking advantage of encrypted mobile messaging services to unleash a wave of sophisticated smishing attacks targeting organizations across more than 100 countries. If an executive's phone gets hacked, it will open a new gateway into highly valuable information," Savolainen said.