Docker Breach

NJCCIC Data Breach Notification

Original Release Date: 2/18/2020

Summary

Security researchers from Palo Alto Networks discovered some organizations—including research institutes, retailers, news media organizations, and technology companies—have improperly configured Docker registries. They found 117 unsecured Docker registries accessible over the public web that permitted image downloads, authorized uploads, and image deletions. The misconfiguration and permitted commands can allow malicious actors to replace images with backdoors, host malware, interrupt business operations, or blackmail for ransom. 

Recommendations

The NJCCIC recommends adding a firewall rule to prevent the registry from being accessible from the public internet and enforce the Authenticate header in all API requests as forms of access control. Please review the Palo Alto Networks article for more information.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.