Container images used in cloud deployments often contain unnecessary components, leading to hundreds of vulnerabilities per image, as highlighted by studies from Chainguard and NetRise. To address this, several companies, including Docker and BellSoft, are developing and promoting hardened container images that strip out non-essential software, package managers, and other potential attack vectors. These slimmed-down images are designed to include only the minimum required components, significantly reducing the number of known vulnerabilities and improving the overall security posture of containerized applications.
BellSoft has introduced its own Hardened Images, focusing on Java runtime optimization, custom maintenance for Alpaquita Linux OS, and proactive vulnerability remediation. This approach aligns with a broader industry trend, with vendors like Chainguard and Docker also offering secure, minimal images to help developers deploy safer applications in Kubernetes and other cloud-native environments. The adoption of hardened images is seen as a critical step in mitigating the growing threat of container-targeted cyberattacks and streamlining security processes for organizations relying on container technology.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
BellSoft announced Hardened Images, a container security offering aimed at reducing vulnerabilities in containerized environments by using more secure base images. The launch was reported as a response to rising cyber threats and common weaknesses in standard container images.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.