❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 19 December 2025Main stream

Docker Fixes β€˜Ask Gordon’ AI Flaw That Enabled Metadata-Based Attacks

19 December 2025 at 07:46
Pillar Security has identified a critical indirect prompt injection vulnerability in Docker’s β€˜Ask Gordon’ assistant. By poisoning metadata on Docker Hub, attackers could bypass security to exfiltrate private build logs and chat history. Discover how the "lethal trifecta" enabled this attack and why updating to Docker Desktop 4.50.0 is essential for developer security.
❌
❌