<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Docker Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Docker.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:52 GMT</lastBuildDate><item><title>Recent DShield SIEM Update</title><link>https://isc.sans.edu/diary/rss/33156</link><guid isPermaLink="false">cst-2542</guid><description>DShield SIEM received an update in September 2025 that added TTY log collection and Suricata integration to its monitoring capabilities. The system now uses ELK stack version 8.19.15 and includes additional dashboards that allow security practitioners to review command activity on DShield sensors, with logs parsed and uploaded daily and cross-linked across visualizations.</description><pubDate>Wed, 15 Jul 2026 01:38:43 GMT</pubDate></item><item><title>Critical Gitea Flaw Under Active Exploitation, Researchers Warn</title><link>https://securityweek.com/critical-gitea-flaw-under-active-exploitation-researchers-warn</link><guid isPermaLink="false">cst-545</guid><description>A critical vulnerability in Gitea (CVE-2026-20896) allows attackers to bypass authentication by manipulating a single HTTP header, granting access to repositories and secrets. Researchers have confirmed the flaw is under active exploitation in the wild.</description><pubDate>Tue, 07 Jul 2026 17:17:19 GMT</pubDate></item><item><title>Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure</title><link>https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html</link><guid isPermaLink="false">cst-486</guid><description>Threat actors have begun probing a critical vulnerability in Gitea Docker images (CVE-2026-20896, CVSS 9.8) just 13 days after its disclosure. The flaw allows unauthenticated users to bypass authentication by spoofing the X-WEBAUTH-USER header, enabling elevated privilege access to the DevOps platform.</description><pubDate>Mon, 06 Jul 2026 16:28:59 GMT</pubDate></item><item><title>PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale</title><link>https://sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale</link><guid isPermaLink="false">cst-606</guid><description>SentinelLABS discovered PCPJack, a credential theft worm that targets exposed cloud infrastructure including Docker, Kubernetes, Redis, and MongoDB, while removing artifacts from the TeamPCP threat actor group. The framework harvests credentials from cloud services, containers, developer tools, and financial applications, then spreads to additional hosts via a dropper script that downloads Python-based modules from attacker-controlled infrastructure. Unlike typical cloud malware, PCPJack does not deploy cryptominers, instead suggesting monetization through credential fraud, spam campaigns, extortion, or resale of stolen access.</description><pubDate>Thu, 07 May 2026 10:00:17 GMT</pubDate></item><item><title>CI/CD pipeline abuse: the problem no one is watching</title><link>https://elastic.co/security-labs/detecting-cicd-pipeline-abuse-with-llm-augmented-analysis</link><guid isPermaLink="false">cst-630</guid><description>Attackers are increasingly targeting CI/CD pipelines rather than production systems directly, compromising developer credentials and modifying workflow files to exfiltrate secrets at scale. The article details specific attack patterns including the GhostAction campaign (327 users, 3,325 stolen secrets), the Shai-Hulud npm worm (46,000 malicious packages), and automated scanning for misconfigurations like the pull_request_target trigger. A new open-source tool, cicd-abuse-detector, has been released to identify suspicious pipeline modifications across GitHub Actions, GitLab CI, and Azure DevOps using regex patterns and language model analysis.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Docker and Kubernetes, we have got you covered: Wiz simplifies compliance and security posture management for Docker and Kubernetes environments.</title><link>https://wiz.io/blog/docker-and-kubernetes-we-have-got-you-covered-wiz-simplifies-compliance-and-secur</link><guid isPermaLink="false">cst-1689</guid><description>Wiz announced new capabilities to help organizations manage security posture and compliance for Docker and Kubernetes environments against CIS benchmarks. The offering provides reporting and remediation guidance for identified issues.</description><pubDate>Mon, 21 Aug 2023 16:55:51 GMT</pubDate></item></channel></rss>