> Markdown version of [/events/world-congress-2026-north-america/sessions/1755-your-registry-can-t](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1755-your-registry-can-t). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Your registry can't stop a valid login. What happens then? - **Date:** Friday, Sep 25, 2026 - **Time:** 09:40–10:10 (30 min) - **Room:** Stage 4 - **Event:** World Congress 2026 North America ## Recording [Watch recording](https://www.wearedevelopers.com/videos/100445-your-registry-can-t-stop-a-valid-login-what-happens-then) ## Description On April 22, 2026, a threat actor used stolen Checkmarx credentials to push malicious images to a trusted Docker Hub repository. The payload quietly collected scan output, encrypted it, and exfiltrated it to attacker-controlled infrastructure. Docker's registry monitoring flagged the push for review within about half an hour, the repository was quarantined, and Docker worked side by side with Socket and Checkmarx to shut it down. This talk is about how. Not the incident itself, but the detection model behind it: what signals fired, why no single one was enough, and what it means to build a supply chain posture where the question is not "can we prevent every breach" but "how fast can we find it and how small is the blast radius." We cover the structural pattern behind Trivy, KICS, LiteLLM and axios: stolen credentials, legitimate publishing flows, short exposure windows. Then we get into what Docker actually does differently: provenance-linked builds, digest pinning, cooldown periods, cross-registry signal sharing, and Docker Hardened Images as the foundation that sits outside the attack surface entirely. You leave with a concrete checklist your team can act on tomorrow, and a mental model that holds regardless of which tool gets hit next. ## Speaker ### [Khushboo Verma](https://www.wearedevelopers.com/@khushboo-verma) Systems Engineer at Cloudflare ## Related talks at this congress - [Stop Running Mystery Meat in Production](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1726-stop-running-mystery) — Jeroen van Erp - [Securing the Agentic Stack: Docker Hardened Images and Supply Chain Security](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1882-securing-the-agentic) — Ajeet Raina - [rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1718-rm-rf-horror-stories) — Rishab Kumar - [One Boundary for the Agentic Era](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1871-one-boundary-for-the) — Mark Lechner