- EverythingDevOps
- Posts
- Weekend RoundUp: Top 9 Docker Container Security Vulnerabilities
Weekend RoundUp: Top 9 Docker Container Security Vulnerabilities
Docker’s popularity has made it a prime target. These nine vulnerabilities reveal where most teams slip up and how to stay secure.

Hey there,
It's finally Friday🥳!
Before you sign off for the weekend, we've wrapped up a few things you need to know in one tidy package.
Scroll down for this week's compelling top picks, a rundown of upcoming events, and a curated list of the latest job opportunities we think you'll love.

📰Top Picks:
Cisco warns of new firewall attack variant
Cisco says a fresh wave of attacks is hitting its Secure Firewall devices, exploiting flaws that have been active for months. The company also patched two critical bugs in its contact center software that could let attackers run commands with root access. Read more.
Top 9 Docker Container Security Vulnerabilities
42% of teams are worried about container security. The threats are real: unpatched runC, exposed Secrets, and critical GPU flaws. If you use Docker, it's essential to be aware of these nine container vulnerabilities and how to patch them before they're exploited. Read more.
Kong adds MCP testing to Insomnia
Kong’s Insomnia 12 now supports the Model Context Protocol (MCP), letting developers design, debug, and test MCP clients and servers alongside regular APIs. Read more.
Senate bill targets AI-linked layoffs amid job cuts surge
US Senators Josh Hawley and Mark Warner have proposed a bill that would make companies report layoffs tied to AI and automation. The move comes as October job cuts hit a 20-year high. Read more.
Grafana and GitLab connect CI/CD to observability
GrafanaLabs has released a new open-source integration that streams GitLab CI/CD events into Grafana Cloud Logs using a serverless setup. Read more.
Gateway API 1.4.0 goes GA for Kubernetes
The new Gateway API release brings BackendTLSPolicy for secure gateway-to-backend traffic, named route rules, and clearer GatewayClass capabilities. Read more.
MCP Servers solve connectivity, not control
MCP makes it easy for AI agents to plug into tools like Slack and Jira, but managing access and compliance remains messy. Many teams are realizing that connecting systems is simple, but the real challenge is keeping those connections secure. Read more.
The State of Global Open Source 2025
LF Research and Canonical’s latest survey shows open source is more vital than ever, but governance and security still lag behind its rapid growth. Download the report here.
Was this email forwarded to you? Subscribe here to get your weekly updates directly into your inbox.
🗓️ Upcoming Events
Mark your calendars!
SQL Saturday Oregon & SW Washington 2025 (15 November 2025): A free, community-driven event for data professionals looking to sharpen their SQL, BI, and analytics skills with hands-on sessions and expert-led discussions. Register here.
DevFest Lusaka 2025 (15 November 2025): Zambia’s biggest tech community event celebrates innovation and developer growth with workshops and talks across cloud, mobile, and web technologies. Register here.
DevFest Raipur 2025 (15 November 2025): A vibrant day of learning and collaboration for developers in Raipur, featuring sessions on AI, Android, Flutter, and web technologies. Register here.
DevFest Seattle ( 18 November 2025): Seattle’s developer community gathers for a day of practical tech sessions, networking, and talks led by Google Developer Experts and industry leaders. Register here.
React Summit US (18 November 2025): The leading React conference in the US brings together frontend developers and React experts for deep dives into frameworks, tools, and best practices. Get your tickets.
Microsoft Ignite 2025 (18-21 November 2025, San Francisco, Free online): Microsoft’s premier tech conference returns with in-person and free online sessions exploring AI, cloud, and the future of enterprise development. Register here.
SREDAY Site Reliability, DevOps and Cloud (19–20 November 2025, Paris, France): Paris hosts two days dedicated to SRE, DevOps, and cloud innovation with global experts sharing insights on scalability, automation, and reliability. Get your ticket.
BSides Ottawa 2025 (20 November 2025): A community-driven cybersecurity conference where researchers, engineers, and practitioners share insights on emerging security trends, tools, and vulnerabilities. Register here.
DevFest Paris 2025 (21 November 2025): The Paris edition of Google’s global developer festival brings together experts in AI, Android, cloud, and web for a day of learning and collaboration. Register here.
DevFest Birmingham 2025 (21 November 2025): The Birmingham developer community gathers for hands-on sessions, networking, and talks covering mobile, web, and AI innovation. Register here.
Michigan DevFest 2025 (21–22 November 2025): A two-day celebration of developers in the Midwest, featuring workshops, live coding, and discussions around open source, AI, and modern app development. Register here.
DevFest London 2025 (22 November 2025): London’s tech community unites for talks and workshops on cloud, AI, and modern web development, led by Google Developer Experts. Register here.
DevFest Berlin 2025 (22 November 2025): Berlin hosts its annual DevFest, blending local expertise and global perspectives on AI, Flutter, and web technologies. Get your ticket.
DevFest Port Harcourt 2025 (22 November 2025): Nigeria’s vibrant developer community comes together for a full day of sessions, networking, and skill-building across cloud, mobile, and AI. Register here.
Python Sul 2025 (22–24 November 2025, Brazil): The regional Python conference for southern Brazil returns with workshops, keynotes, and community-driven discussions on Python in data, AI, and web development. Get your ticket.
Opportunities:
Platform Engineer at OakNorth - United Kingdom (Hybrid)
Cloud Operations Engineer at MongoDB - San Francisco, US
Cloud Deployment Engineer II at Qumulo - Seattle, WA (Remote)
Cloud Platform Engineer at CGI - US (Remote)
Cloud Platform Engineer, Associate at Morgan Stanley - Bengaluru, Karnataka, India
Cloud Support Engineer at Akamai - India (Remote)
Cloud Operations Engineer at Signify - Bangalore, India
Cloud Engineer at SmartSuite - United States (Remote)
Software Engineer, Cloud Infrastructure at Notion - United States (Hybrid)
Site Reliability Engineer I at Axon - United States (Remote)
Senior Backend Engineer (Puppet) at Fireflies.ai - Multiple locations (Remote)
DevOps Engineer AWS / Azure at Preservica - Oxfordshire, UK
Platform Engineer at Zopa Bank - Manchester (Hybrid)
Azure Platform Engineer at FCA - Edinburgh, London (Hybrid)
DevOps Engineer at McAfee - US (Hybrid)
Platform Engineer II at Mastercard - Multiple locations, US (Hybrid)
DevOps Engineer II at Esri - Edinburgh, UK
Infrastructure Support Engineer at Nscale - London (On-site)
Cloud Platform Engineer - Sr Analyst at Nasdaq - Bangalore, India
AWS Platform Engineer at CSG - India (Remote)
DevOps Engineer at GE Vernova’s - Hyderabad, India (On-site)
Got a sec?
Just two questions. Honest feedback helps us improve. No names, no pressure.
And it’s a wrap!
If you found this helpful, share this link with a colleague or fellow DevOps engineer.
Have a restful weekend!
Divine Odazie
Founder of EverythingDevOps