Exposed Credentials in Over 10,000 Docker Hub Images
Summary
Hide ▲
Show ▼
More than 10,000 Docker Hub container images were found to expose sensitive data, including live credentials, AI model keys, and authentication tokens. The leaks impact over 100 organizations, including a Fortune 500 company and a major national bank. The exposed secrets pose significant risks, as they often provide full access to cloud environments, Git repositories, CI/CD systems, and other critical infrastructure components. The most frequent secrets found were access tokens for AI models, with 4,000 such keys identified. Many of the leaks originated from 'shadow IT' accounts, which fall outside of stricter corporate monitoring mechanisms. Despite some developers removing leaked secrets, 75% of the exposed keys were not revoked, leaving them vulnerable to exploitation.
Timeline
-
10.12.2025 20:22 1 articles · 5h ago
Over 10,000 Docker Hub Images Leak Sensitive Credentials
Security researchers at Flare discovered that 10,456 Docker Hub container images exposed sensitive data, including live credentials and AI model keys. The leaks impact over 100 organizations, with 42% of the images exposing at least five sensitive values. Many of the leaks originated from 'shadow IT' accounts, and 75% of the exposed keys were not revoked, leaving them vulnerable to exploitation.
Show sources
- Over 10,000 Docker Hub images found leaking credentials, auth keys — www.bleepingcomputer.com — 10.12.2025 20:22
Information Snippets
-
Over 10,000 Docker Hub container images expose sensitive data, impacting more than 100 organizations.
First reported: 10.12.2025 20:221 source, 1 articleShow sources
- Over 10,000 Docker Hub images found leaking credentials, auth keys — www.bleepingcomputer.com — 10.12.2025 20:22
-
The exposed secrets include live credentials to production systems, CI/CD databases, and AI model keys.
First reported: 10.12.2025 20:221 source, 1 articleShow sources
- Over 10,000 Docker Hub images found leaking credentials, auth keys — www.bleepingcomputer.com — 10.12.2025 20:22
-
42% of the scanned images exposed at least five sensitive values.
First reported: 10.12.2025 20:221 source, 1 articleShow sources
- Over 10,000 Docker Hub images found leaking credentials, auth keys — www.bleepingcomputer.com — 10.12.2025 20:22
-
The most frequent secrets were access tokens for AI models, with 4,000 such keys identified.
First reported: 10.12.2025 20:221 source, 1 articleShow sources
- Over 10,000 Docker Hub images found leaking credentials, auth keys — www.bleepingcomputer.com — 10.12.2025 20:22
-
Many of the leaks originated from 'shadow IT' accounts, which are not under strict corporate monitoring.
First reported: 10.12.2025 20:221 source, 1 articleShow sources
- Over 10,000 Docker Hub images found leaking credentials, auth keys — www.bleepingcomputer.com — 10.12.2025 20:22
-
Only 25% of developers revoked exposed secrets within 48 hours, leaving 75% of the keys vulnerable.
First reported: 10.12.2025 20:221 source, 1 articleShow sources
- Over 10,000 Docker Hub images found leaking credentials, auth keys — www.bleepingcomputer.com — 10.12.2025 20:22