🔒🤖 The Next Step in GitGuardian’s Approach to NHI Security

DISCOVER

🔒🤖 The Next Step in GitGuardian’s Approach to NHI Security

DISCOVER
No items found.

Kubecon + Cloudnativecon Europe

Join us at KubeCon + CloudNativeCon Europe 2025! Our team will be presenting groundbreaking research on cybersecurity in the cloud-native ecosystem—don’t miss our talk. We’d love to connect! Schedule a meeting with us to discuss how we can collaborate and innovate together. See you there! 🚀

EMEA
Conference
Apr 01, 2025 - Apr 04, 2025

ExCeL London

ExCeL London

Join us, be part of the vision!

By submitting this form, I agree to GitGuardian’s Privacy Policy

Thank you! Your registration has been recorded!
Oops! Something went wrong while submitting the form.

Join us at KubeCon + CloudNativeCon Europe 2025! Our team will be presenting groundbreaking research on cybersecurity in the cloud-native ecosystem—don’t miss our talk. We’d love to connect! Schedule a meeting with us to discuss how we can collaborate and innovate together. See you there! 🚀

No items found.

More info on this event

Speakers

Guillaume Valadon

Guillaume Valadon

Cybersecurity Researcher

Agenda

Fire icon
April 4, 2025 2:30 PM

Fresh Secrets From the Docks: Lessons Learnt From Analyzing 180,000 Public DockerHub Images

Hardcoded secrets remain a common practice in containerized environments, often used for convenience during testing or deployment, despite their significant, well-known security risks.

Docker images are not immune and can inadvertently leak secrets through Dockerfiles, configuration files, or image layers. Once pushed to registries such as DockerHub, these secrets become discoverable to attackers, putting environments at risk.

In this session, we will share insights from an extensive analysis of 180,000 public Docker images retrieved from DockerHub, uncovering a staggering number of 35,000 secrets from 18,000 images. More than 6,000 of these secrets were valid when the study was conducted in late 2024, including AWS keys, GCP keys, OpenAI tokens, and GitHub tokens belonging to Fortune 500 companies.

Finally, we will discuss common misuses and pitfalls in Dockerfile files that lead to secrets being leaked, and describe best practices for handling secrets in Docker images.

đź“Ť Level 1 | Hall Entrance S10 | Room D

No items found.

Break

Reserve your spot now!

Join GitGuardian and their crew!

Guillaume Valadon

Join us, be part of the vision!

By submitting this form, I agree to GitGuardian’s Privacy Policy

Thank you! Your registration has been recorded!
Oops! Something went wrong while submitting the form.