Skip to content

Topic

Container Security

Securing container images and runtimes, including image composition, hardening and vulnerability management.

Current stories

security1 publisher

EU's Cyber Resilience Act puts Helm chart and Kubernetes operator vendors on a 24-hour exploit clock

EU Cyber Resilience Act rules have required 24-hour ENISA warnings on exploited flaws in commercial container images since Sept. 11, 2026. Vendors of supported Kubernetes operators and Helm charts are on the same clock, well before the rest of the law is enforced in December 2027.

Reality

Evidence50
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence55
security3 publishers

CARBONATO botnet infects Docker hosts, prioritizing theft of AI provider API keys

CARBONATO, a Docker botnet running since October 2024, hijacks hosts on open port 2375 and steals keys from 14 AI providers to fund its own LLM gateway. ThreatDown found the crew's own container registry exposed, handing defenders 4.3 GB of its toolchain.

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 57%
Investor
Investor 10%

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives35
Confidence60
security6 publishers

CISA gives agencies one business day to patch three exploited Linux kernel flaws

The three kernel CVEs CISA added to its exploited-bugs catalog on Friday all need local access, and the lowest-scored of them is the one STAR Labs used for privilege escalation and container escape. Red Hat has confirmed public exploit code.

Perspective Coverage

6 publishers
Builder
Builder 30%
Operator
Operator 57%
Investor
Investor 13%

Reality

Evidence74
Adoption68
Hype gap−8
Incentives38
Confidence76