A wave of escalating software supply chain attacks—including the axios npm compromise attributed to North Korea's Lazarus Group, the TeamPCP campaign, and GlassWorm—has prompted Docker's CISO to outline concrete defensive practices. The core problem is implicit trust: organizations trust container tags, GitHub Actions, and
Table of contents
The common thread is implicit trustSecure your foundationsSecure your CI/CDSecure your endpointsSecure your AI developmentBuild muscle for incident responseThe landscape has changed, your defaults should tooSort: