Docker and JFrog partner to further secure Docker Hub and remove millions of imageless repos with malicious links

Like any large platform on the internet (such as GitHub, YouTube, GCP, AWS, Azure, and Reddit), Docker Hub, known for its functionality and collaborative environment, can become a target for large-scale malware and spam campaigns. Today, security researchers at JFrog announced that they identified millions of spam repositories on Docker Hub without images that have malicious links embedded in the repository descriptions/metadata. To be clear, no malicious container images were discovered by JFrog. Rather, these were pages buried in the web interface of Docker Hub that a user would have to discover and click on to be at any risk. We thank our partner JFrog for this report, and Docker has deleted all reported repositories. Docker also has a security@docker.com mailbox, which is monitored by the Security team. All malicious repositories are removed once validated.

The JFrog report highlights methods employed by bad actors, such as using fake URL shorteners and Google’s open redirect vulnerabilities to mask their malicious intent. These attacks are not simple to detect — many are not malware but simple links, for example, and wouldn’t be detectable except by humans or flagged as malicious by security tools. 

JFrog identified millions of “imageless” repositories on Docker Hub. These repositories, devoid of actual Docker images, serve merely as fronts for distributing malware or phishing attacks. Approximately 3 million repositories were found to contain no substantive content, just misleading documentation intended to lure users to harmful websites. The investment in maintaining Hub is enormous on many fronts.

These repositories are not high-traffic repositories and would not be highlighted within Hub. The below repository is an example highlighted in JFRog’s blog. Since there is not an image in the repository, there will not be any pulls.

An image would be displayed below with a corresponding tag. These repositories are empty.

Conclusion

Docker is committed to security and has made substantial investments this past year, demonstrating our commitment to our customers. We have recently completed our SOC 2 Type 2 audit and ISO 27001 certification review, and we are waiting on certification. Both SOC 2 and ISO 27001 demonstrate Docker’s commitment to Customer Trust and securing our products. 

We urge all Docker users to use trusted content. Docker Hub users should remain vigilant, verify the credibility of repositories before use, and report any suspicious activities. If you have discovered a security vulnerability in one of Docker’s products or services, we encourage you to report it responsibly to security@docker.com. Read our Vulnerability Disclosure Policy to learn more.

Docker is committed to collaborating with security experts like JFrog and the community to ensure that Docker Hub remains a safe and robust platform for developers around the globe. 
Quelle: https://blog.docker.com/feed/

AWS Resilience Hub ist jetzt ein HIPAA-fähiger Service

AWS Resilience Hub ist jetzt ein HIPAA-fähiger Service, der es Organisationen aus dem Gesundheitswesen und den Biowissenschaften ermöglicht, AWS Resilience Hub für die Ausführung vertraulicher Workloads zu verwenden, für die in den USA der Health Insurance Portability and Accountability Act (HIPAA) gilt. AWS unterhält ein auf Standards basierendes Risikomanagementprogramm, um sicherzustellen, dass die HIPAA-fähigen Services insbesondere die administrativen, technischen und physischen HIPAA-Schutzmaßnahmen unterstützen. 
Quelle: aws.amazon.com

R6gd-Instances von Amazon EC2 sind jetzt in der Region Europa (Zürich) verfügbar

Ab heute sind R6gd-Instances von Amazon Elastic Compute Cloud (Amazon EC2) in der Region Europa (Zürich) verfügbar. Diese Instances werden mit AWS-Graviton2-Prozessoren betrieben und basieren auf dem AWS Nitro System. Das Nitro System ist eine Sammlung von AWS-entwickelten Hardware- und Software-Innovationen, die die Bereitstellung effizienter, flexibler und sicherer Cloud-Services mit isolierter Multi-Tenancy, privaten Netzwerken und schnellem lokalen Speicher ermöglichen. R6gd-Instances bieten lokalen SSD-Speicher und eignen sich ideal für speicherintensive Workloads wie Open-Source-Datenbanken, In-Memory-Caches und Big-Data-Analytik in Echtzeit, die Zugriff auf Hochgeschwindigkeitsspeicher mit geringer Latenz benötigen. Diese Instances bieten bis zu 25 Gbit/s Netzwerkbandbreite, bis zu 19 Gbit/s Bandbreite zu Amazon Elastic Block Store (Amazon EBS) und bis zu 512 GiB RAM und bis zu 3,8 TB an lokalem NVMe-SSD-Instance-Speicher.
Quelle: aws.amazon.com

Amazon WorkSpaces vereinfacht die BYOL-Kontoverwaltung (Bring Your Own License)

Amazon WorkSpaces stellt Ihnen jetzt APIs zur Verknüpfung Ihrer AWS-Konten innerhalb derselben Region zur Verfügung, sodass diese Konten dieselbe zugrunde liegende dedizierte Infrastruktur nutzen können. AWS ermöglicht die Ausführung Ihrer Bring Your Own License (BYOL)-WorkSpaces auf einer für Sie eingerichteten Infrastruktur in der AWS Cloud. Außerdem erleichtern die neuen APIs Ihnen die effiziente Nutzung Ihrer dedizierten Infrastruktur. 
Quelle: aws.amazon.com

AWS Elastic Disaster Recovery unterstützt jetzt AWS-Outposts-Racks

Heute kündigt AWS Elastic Disaster Recovery (AWS DRS) die Unterstützung von AWS-Outposts-Racks an. Mit dieser Neuerung können Sie jetzt Ihre Datenreplikations- und Wiederherstellungsziele auf AWS-Outposts-Racks festlegen, zusätzlich zur Nutzung von AWS-Regionen und Availability Zones, in denen AWS DRS verfügbar ist.
Quelle: aws.amazon.com