Docker Hub, One of the largest repositories for Docker container images has now become the latest victim of a security breach. As confirmed by the firm, the Docker Hub data breach resulted in the compromise of sensitive information. The incident affected around 190,000 user accounts.
Docker Hub is an online repository service where users and partners can create, test, store and distribute Docker container images, both publicly and privately.
The breach reportedly exposed sensitive information for nearly 190,000 Hub users (that's less than 5 percent of total users), including usernames and hashed passwords for a small percentage of the affected users, as well as Github and Bitbucket tokens for Docker repositories.
Docker Hub started notifying affected users via emails informing them about the security incident and asking them to change their passwords for Docker Hub, as well as any online account using the same password.
Regarding the kind of information exposed, Docker Hub stated,
“Data includes usernames and hashed passwords for a small percentage of users as well as GitHub and Bitbucket tokens for Docker autobuilds.” "On Thursday, April 25th, 2019, we discovered unauthorized access to a single Hub database storing a subset of non-financial user data. Upon discovery, we acted quickly to intervene and secure the site.”

"For users with autobuilds that may have been impacted, we have revoked GitHub tokens and access keys, and ask that you reconnect to your repositories and check security logs to see if any unexpected actions have taken place."
The company has not revealed any further details about the security incident or how the unknown attackers gained access to its database.
The firm have also revoked Docker autobuild tokens, those using this service have to relink their GitHub or Bitbucket repositories to Docker Hub. The company is also working to enhance its overall security processes and reviewing its policies following the breach.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.



