VOOZH about

URL: https://thenewstack.io/why-containers-are-sweet-targets-for-ransomware-attacks/

⇱ Why Containers Are Sweet Targets for Ransomware Attacks - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2019-04-04 15:00:11
Why Containers Are Sweet Targets for Ransomware Attacks
podcast,sponsor-palo-alto-networks,sponsored,sponsored-podcast,the-new-stack-makers,
Containers / Security

Why Containers Are Sweet Targets for Ransomware Attacks

Apr 4th, 2019 3:00pm by B. Cameron Gain
👁 Featued image for: Why Containers Are Sweet Targets for Ransomware Attacks
Feature image via Unsplash.
Palo Alto Networks sponsored this post.


Why Containers Are Sweet Targets for Ransomware Attacks

Ransomware and other attacks are becoming increasingly common, as black hats discover how cloud native and other newer platforms can serve as softish targets. With the recently revealed Docker runtime exploit as an example of what can go terribly wrong, the pressure is obviously on security providers to stay ahead of the game — but finding the right solution for this new world of computer protection can mean the difference between a thriving architecture, or in the worst case, a complete shutdown of an organization’s operations.

What to look for in the way of security solutions for cloud native, as well as serverless and more mature platforms were the main subjects in this episode of The New Stack Makers podcast with Neil Carpenter, a solutions architect for Twistlock, hosted by Alex Williams, founder and editor-in-chief of The New Stack.

The obvious and sometimes overlooked assumption is attackers will seek the easiest targets. Previously, Carpenter described how desktops were especially vulnerable ransomware targets before moving into some server environments, culminating in especially nefarious attacks in the healthcare and education sectors in 2016 and 2017.

“This was a way to monetize these attacks,”  Carpenter said.

Still, ransomware attacks are challenging to orchestrate. Carpenter described how an attacker’s attempt to run malware on a desktop, for example, in order to encrypts all of the documents and data until the victim buys pays a ransom in Bitcoin or another cryptocurrency.

Prisma Cloud delivers the industry’s broadest security and compliance coverage — for applications, data, and the entire cloud native technology stack — throughout the development lifecycle and across multi- and hybrid-cloud environments.
Learn More
The latest from Palo Alto Networks

But finding a Kubernetes cluster with an unauthenticated endpoint or an unpatched vulnerability on a Docker server accessible with an Internet connection represents a particularly attractive target.

“[As an attacker], I can drop my crypto miner directly on what you’re running and schedule it to run on your Kubernetes cluster and then I don’t have to deal with helping you figure out how to buy Bitcoin and get it to me. I just run my miner and it runs on your CPU and takes up,” Carpenter said. “I think, for an attacker, it’s elegant, (which is probably not really the word I’m looking for), but it’s simple and a lot simpler than the other approaches that they had to monetize that sort of attack.”

With Twistlock’s Runtime Application Self Protection (RASP) Defender, the idea was to embed security capabilities within applications as opposed to offering external — and more unwieldy and less-effective — protection for Kubernetes and containers running in cloud-native environments, as well as for serverless and other platforms, Carpenter said.

“So, the idea is we’re taking those protections and instead running them on these hosts that you own, since we’re baking them into the application itself and into the code that you are deploying, so that wherever that runs, it gets that same level of protection and visibility,” Carpenter said. “You can automate this into your pipeline as you deploy it and then protect those workloads.”

The idea is to limit the extent to which your developers have to manage to embed this into the code itself, Carpenter said.

“So, instead, this is conceptually a wrapper around the things that they’re deploying instead of having to really change your development processes and change the approach that you’re taking,” Carpenter said. “What we’re doing is giving you the tools to wrap these things with the RASP Defender and then deploy them in random wherever they go.”

In this Edition:

1:09: What is RASP Defender.
6:17: How you use RASP Defender as a wrapper for a Fargate task
10:43: Think about this differently with different cloud services.
12:22: Deploying containers in more distributed environments?
14:25: Some tips.
18:21: How to think about RASP Defender.

Prisma Cloud delivers the industry’s broadest security and compliance coverage — for applications, data, and the entire cloud native technology stack — throughout the development lifecycle and across multi- and hybrid-cloud environments.
Learn More
The latest from Palo Alto Networks
TRENDING STORIES
BC Gain is founder and principal analyst for ReveCom Media. His obsession with computers began when he hacked a Space Invaders console to play all day for 25 cents at the local video arcade in the early 1980s. He then...
Read more from B. Cameron Gain
Palo Alto Networks sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Pragma, Docker.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.