This page was machine-translated and may differ from the original. View original
Aqua Security: “Security Risks to Thousands of Organizations, Including Fortune 500s”
250 million security vulnerabilities discovered in companies worldwide
Aqua Security, a pioneer in cloud-native security, warned that several organizations, including Fortune 500 companies, are exposed to security risks.
Aqua Security announced on the 3rd that its security research team, Aqua Nautilus, discovered 250 million artifacts and 65,600 container images exposed through thousands of misconfigured container images, the Red Hat Quay registry, and the JFrog Artifactory and Sonatype Nexus artifact registries.
Based on the findings of this research team, in many cases, a significant amount of important secrets and sensitive proprietary code was included, posing a risk to five Fortune 500 companies and thousands of other companies.
Registrys and artifact management systems are core elements of the software supply chain and are primary targets for threat actors. Many companies intentionally expose their container and artifact registries externally, often failing to detect or control the leakage of sensitive information and confidential data through these registrars.
If an attacker gains access, there is a possibility of exploiting the entire Software Development Lifecycle (SDLC) toolchain and the artifacts stored within it. According to Aqua's research, if such highly critical environments are not adequately protected or if sensitive information is leaked into the open-source domain, the environment becomes exposed to the internet and vulnerable to attacks, which can lead to serious and fatal attacks.
“When we started this study, our goal was to identify companies with registry configuration errors and to understand how skilled attackers might exploit registries with exposed configuration errors,” said Assaf Morag, Senior Threat Researcher at Aqua Nautilus. “The results of our analysis were surprising and deeply concerning. Given the severity of the risks we discovered, we decided to notify the companies in question.”
Looking at the key findings, Nautilus discovered sensitive keys, including confidential information, credentials, and tokens, on 1,400 individual hosts, and found private and sensitive address information for endpoints such as Redis, MongoDB, PostgreSQL, and MySQL on 156 hosts.
Researchers also found 57 registries with critical configuration errors, 15 of which allowed administrator access with default passwords.
Nautilus detected over 2,100 artifact registries that allow uploads. In these cases, attackers can infect the registries with malware. There were also instances where anonymous user access allowed potential attackers to obtain sensitive information. At this time, confidential information, keys, passwords, etc., can be used to carry out serious software supply chain attacks or infect the SDLC.
Various companies of all sizes around the world have been identified, and two major cybersecurity firms are also included.
IBM, one of the Fortune 500 companies, had its internal container registry exposed to the internet, but after Nautilus released the analysis results, it was able to quickly block internet access to the environment and mitigate all related risks. Other companies identified included Alibaba, Siemens, and Cisco.
Nautilus confirmed that many companies do not have responsible security disclosure programs. A security disclosure program is a crucial tool that allows security researchers to systematically report potential vulnerabilities, enabling companies to quickly resolve issues before being compromised by malicious actors. According to Nautilus, companies with established responsible disclosure programs were able to resolve configuration errors within a week. Companies without such programs, however, had to go through a more difficult and lengthy process.
Katie Norton, Senior Research Analyst for DevOps and DevSecOps at IDC, stated, “The findings from Aqua Nautilus demonstrate the need for developers and application security teams to raise awareness of best practices regarding software supply chain security.” She pointed out, “As code explosions and the use of open source combine with DevOps to accelerate application development and deployment, companies have fallen behind in governance, security controls, and education, and this needs to be rectified.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.














