Security news aggregator

Latest coverage for Containers

Stay secure with the latest insights on container security, trends, and best practices in information security for containerized applications.

41 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

Containers are a lightweight, executable software package that includes everything needed to run a piece of software, including the code, runtime, system tools, libraries, and settings. They are isolated from each other and the host system, providing a consistent operating environment across different development, testing, and production settings.

In the context of information security, containers represent both a challenge and an opportunity. They can enhance security by isolating applications and reducing the attack surface compared to running applications directly on the host or in virtual machines. However, they also introduce new security considerations such as container escape vulnerabilities, image security, orchestration security, and the need for proper container lifecycle management. Ensuring the security of containers involves securing the container images, the container runtime, the container orchestration system, and the underlying infrastructure. It requires continuous vulnerability management, proper network configurations, access controls, and monitoring of container activities. Security tools and policies must be adapted to account for the dynamic and ephemeral nature of containers.

Volume over time

Weekly headline count for the current query.

Showing 20 most recent headlines of 41 Filtered view

Dirty Frag is a newly disclosed Linux local privilege escalation vulnerability affecting kernel networking and memory-fragment handling components including esp4, esp6, and rxrpc. The vulnerability enables reliable escalation from an unprivileged user to root and may be leveraged after initial compromise through SSH access, web shells, containers, or low-privileged accounts. Microsoft Defender is actively monitoring limited in-the-wild activity and provides detection coverage for exploitation attempts. The post Active attack: Dirty Frag Linux vulnerability expands post-compromise risk appeared first on Microsoft Security Blog.

BellSoft survey finds 48% prefer pre‑hardened images over managing vulnerabilities themselves Java developers still struggle to secure containers, with nearly half (48 percent) saying they'd rather delegate security to providers of hardened containers than worry about making their own container security decisions.…

Dutchman fails to convince judges his trial was unfair because cops read his encrypted chats A Dutch appeals court has kept a seven-year prison sentence in place for a man who hacked port IT systems with malware-stuffed USB sticks to help cocaine smugglers move containers, brushing off claims that police shouldn't have been reading his encrypted chats.…

Bank Info Security 4 months, 4 weeks ago

Why Palo Alto Is Eyeing a $400M Buy of Endpoint Vendor Koi

Deal Represents Return to Tuck-In M&A for Palo After 3 Multi-Billion Dollar DealsPalo Alto Networks is in talks to buy Washington D.C-based endpoint security startup Koi for $400 million. Koi is focused on securing extensions, AI models, code packages and containers, and its differentiation lies in mapping, assessing risk and govern the software landscape at enterprise scale.

Bank Info Security 5 months ago

Hypervisors - the Next Big Target in 2026

AI Adoption Putting Hypervisors in Attackers Sights, Says Google Cloud's Jamie CollierHypervisors and virtualized infrastructure are drawing more cyberattacks, a trend that reflects organizations' expanded use of cloud services, containers and artificial intelligence-driven systems, said Jamie Collier, lead threat intelligence advisor for the EMEA region at Google Cloud.

Bank Info Security 5 months, 2 weeks ago

Echo Secures $35M to Tackle Cloud Vulnerabilities With AI

Secure-by-Design Startup Uses AI Agents to Safeguard Containers, VMs and LibrariesCloud security startup Echo has closed a $35 million Series A funding round to boost development of its AI-native OS. The platform starts with secure container images and aims to extend to VMs and libraries, helping enterprises minimize risk from open-source software.

Cybersecurity researchers have disclosed details of a new botnet that customers can rent access to conduct distributed denial-of-service (DDoS) attacks against targets of interest

The security landscape for cloud-native applications is undergoing a profound transformation. Containers, Kubernetes, and serverless technologies are now the default for modern enterprises, accelerating delivery but also expanding the attack surface in ways traditional security models can’t keep up with

Just-in-Time, Database, Kubernetes Access Fuel Privileged Access Startup M&ABy acquiring startup Axiom Security, Okta aims to enhance privileged access by offering broader coverage of sensitive assets like Kubernetes containers and databases. The company says the move accelerates value delivery and complements Okta's existing privileged access capabilities.

Startup Says It Cuts Software Vulnerability Volume, Helps Developers Avoid OverloadBacked by YL Ventures and Mayfield, Minimus says its new curated software containers reduce vulnerabilities by over 95%—freeing developers from excessive scanning and patching and reframing the traditional relationship between development and security teams.

Loading more headlines...