Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The often-cited global Docker exposure figures describe internet scans conducted from September through December 2019—not a current census. Unit 42 reported around 5,000 Docker daemons exposed to the internet, estimated that 10–15% of those could be accessed without authentication, and separately collected metadata from more than 1,400 unique unsecured hosts. Those are different measurements, not one count of vulnerable or compromised servers.

How many Docker daemons are exposed to the internet?

Unit 42 periodically scanned internet-exposed Docker daemons between September and December 2019 using Shodan and Censys. Its report states: “Using the Internet of Things search engines Shodan and Censys, we found around 5,000 Docker daemons exposed to the internet and 10-15% of these daemons can be accessed without authentication.” The date range is essential: these figures describe that study period, not the number exposed today. Unit 42’s report

The report also describes a metadata collection involving more than 1,400 unique unsecured Docker hosts, 8,673 active containers, 17,927 Docker images, and 15,229 volumes. These counts refer to the hosts and Docker resources identified in that collection; they are not interchangeable with the roughly 5,000 internet-exposed daemons.

What do the different figures count?

Reported figure What it describes How to read it
Around 5,000 Docker daemons found exposed to the internet by Unit 42 using Shodan and Censys during September–December 2019. A historical count of detected daemons, not a present-day global total or a count of confirmed compromises.
10–15% Unit 42’s estimate of the exposed daemons it found that could be accessed without authentication during the same study period. An estimated share of the exposed-daemon population in that study, not a percentage of all Docker installations.
More than 1,400 unique hosts Unsecured Docker hosts from which Unit 42 collected metadata during September–December 2019. A distinct collection scope; do not add it to the daemon count or treat it as a duplicate-free census of all exposed servers.
8,673 containers; 17,927 images; 15,229 volumes Docker resources identified in Unit 42’s metadata collection from unsecured hosts during the study period. Resource counts, not host counts.

Does an exposed Docker port mean the server is vulnerable?

No. A scan finding means a scanner identified a service matching its query or detection criteria. It does not, by itself, show that the daemon accepts unauthenticated requests, that an attacker can exploit it, or that the system has been compromised. Unit 42’s distinction between daemons detected as exposed and unsecured hosts from which it gathered metadata illustrates why those categories should remain separate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An unsecured, remotely reachable Docker daemon can present serious risk because the daemon operates with high privileges. Unit 42 describes potential container deployment and host access, and reports observed cases involving cryptojacking, containers used to deploy payloads, host filesystem mounts, and credentials or infrastructure details exposed in logs. Those findings establish possible impact and observations in the examined hosts; they do not mean that every exposed daemon was attacked.

What do Shodan and Censys Docker counts actually measure?

Scanner totals depend on what was queried, how the service was identified, what unit was counted, and when observations were collected or refreshed. Shodan documents statistical summaries as facets over results matching a search query. Censys describes its scanning and service-refresh processes. Their indexed results can help identify internet-facing services, but a count from either service is not automatically a verified vulnerability census or a synchronized comparison with the other provider. Shodan’s explanation of facets and search results; Censys scan data documentation

When comparing two exposure claims, check these points before interpreting a difference:

  • Date and window: Is the number a point-in-time observation, a periodic scan, or an aggregation over a longer period? Unit 42’s Docker findings cover September–December 2019.
  • Scanner and query: Which service index and matching criteria produced the result? A change in search or identification rules can change the total.
  • Unit counted: Does the count represent matching services, IP-and-port observations, daemons, or unique hosts? Unit 42 reported both a daemon count and a separate unique-host collection.
  • Validation level: Was the service merely detected, confirmed reachable, confirmed unauthenticated, or observed compromised? Do not infer a stronger finding from a weaker one.
  • Coverage and refresh: What ports and address space were scanned, how was the protocol identified, and how recently was the indexed observation refreshed?
  • Address interpretation: A public IP observation does not, by itself, identify the operator, organization, or affected person. Geographic or hosting-provider distributions are not attribution without separate evidence.

The sources cited here do not establish a newer, directly comparable global count or a synchronized comparison between scanners. Treat a current dashboard result as a dated, provider-specific observation and record the query and retrieval time.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can you secure remote access to the Docker daemon?

If you administer Docker, avoid exposing an unauthenticated daemon to the public internet. Docker’s official documentation covers remote access configuration; Unit 42 recommends restricting access and using authenticated methods. In particular, TLS encryption alone is not enough if clients are not verified: encrypted communication without client-certificate verification can still leave the daemon unauthenticated. Docker remote access documentation; Unit 42’s security recommendations

  • Use the local Unix socket when remote daemon administration is unnecessary.
  • For remote administration, use SSH or correctly configured mutual TLS that verifies client certificates.
  • Allowlist known client IP addresses rather than accepting management traffic from arbitrary internet hosts.
  • Verify that the daemon does not accept unauthenticated public connections.

A scanner listing can be a useful lead for an owner to investigate, but it is not proof of compromise. Do not probe systems you do not own or administer.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.