Home / Companies / Sysdig / Blog / April 2023

April 2023 Summaries

8 posts from Sysdig

Filter
Month: Year:
Post Summaries Back to Blog
Sysdig's March and April 2023 updates highlight significant enhancements across its platform, including the general availability of Sysdig Secure's Container Registry scanning, which adds an extra security layer between pipeline and runtime stages. The company introduced support for Google Cloud Platform (GCP) metrics in Sysdig Monitor, enabling seamless integration and monitoring of GCP services alongside AWS and Azure workloads. Additionally, Sysdig rolled out a new inventory feature as a tech preview, offering a consolidated view of resources and their security posture across cloud, containers, and hosts. The release of Sysdig 6.0 for on-premises users brings product offerings from the SaaS platform to local environments, alongside improvements in threat detection policies, posture controls, and compliance frameworks. Sysdig's updates also include enhancements to its Falco rules, support for the latest CIS benchmarks, and the introduction of advanced visualization tools for threat detection and investigation, aiming to streamline security operations and improve risk management for users.
Apr 27, 2023 4,091 words in the original blog post.
Tales from the Kube!, a comic book special feature by Sysdig, was unveiled at KubeCon + CloudNativeCon Europe 2023 in Amsterdam, providing attendees with an engaging glimpse into the inner workings of a Kubernetes cluster. This creative endeavor is part of Sysdig's ongoing efforts to enhance cloud security, complemented by offerings such as Falco Feeds, which supplies continuously updated, expert-written rules to help companies stay ahead of emerging threats. The comic, scripted by Javier Martínez and illustrated by Xcar Malavida, is now available in a digital format for broader accessibility, aligning with Sysdig's commitment to open-source collaboration and community engagement.
Apr 26, 2023 138 words in the original blog post.
Sysdig has developed a runtime vulnerability management solution integrated with ServiceNow's Container Vulnerability Response (CVR) application to address the challenges of prioritizing and remediating vulnerabilities in container environments. This integration leverages Sysdig's Runtime Insights feature to prioritize vulnerabilities based on real-time usage, helping security and development teams reduce alert fatigue and improve incident response. By automating vulnerability triage, contextualization, and assignment within ServiceNow, users can achieve up to a 95% reduction in vulnerabilities needing immediate attention. The integration also allows for comprehensive risk management by mapping container assets in ServiceNow's Configuration Management Database (CMDB). The collaboration between Sysdig and ServiceNow aims to enhance the efficiency of security workflows and shorten the mean time to resolution (MTTR) for container vulnerabilities.
Apr 25, 2023 1,047 words in the original blog post.
The blog post explores the cost dynamics of using managed services for Prometheus, focusing on leading providers like AWS, Google Cloud, Azure, Grafana Labs, and Sysdig. It highlights that while many companies prefer managed Prometheus services to reduce operational burdens, costs can vary significantly based on the chosen vendor and the specific features required, such as Query Sample Processing (QSP) and storage. Sysdig emerges as the most cost-effective option, offering significant savings compared to others like AWS and Google Cloud, especially under a 10-second metric ingestion interval. The post emphasizes the importance of understanding these costs to avoid unexpected expenses and suggests that Sysdig’s service includes additional benefits like metrics enrichment, eBPF instrumentation, and a Cost Advisor tool to help further reduce operational and infrastructure costs.
Apr 25, 2023 3,944 words in the original blog post.
Sysdig's new Windows Prometheus Bundle offers a streamlined, all-in-one solution for monitoring Windows servers and virtual machines, whether in the cloud or on-premise. By simplifying the installation process, this bundle allows users to deploy a Microsoft Windows installer that includes a Prometheus agent and Windows exporter, which automatically pull and push metrics to Sysdig endpoints. This improved approach not only reduces installation friction by supporting both a user-friendly wizard or command-line interface for large-scale deployments but also enhances performance with a 30% memory improvement. The bundle provides enriched metrics with hostname and domain name labels for better context and installs as a service to ensure continuous operation. Users benefit from comprehensive visibility and control over their Windows infrastructure, alongside the capability to monitor hybrid cloud environments from a single interface.
Apr 13, 2023 1,314 words in the original blog post.
Sysdig has been recognized as a launch partner for AWS's new Cloud Operations Competency, designed to help organizations manage hybrid cloud environments with a focus on governance, financial management, monitoring, observability, compliance, and auditing. This competency highlights Sysdig's expertise in compliance and auditing, as well as monitoring and observability, by providing AWS customers with tools to manage cloud infrastructure and identify risks. Sysdig's solutions assist in continuous compliance management and security monitoring, enabling forensic analysis through activity audits and enhancing cloud visibility to meet user and business expectations. The partnership with AWS underscores Sysdig's commitment to securing cloud innovation by automating governance enforcement and providing runtime insights, while also offering cost-effective solutions for Kubernetes environments.
Apr 06, 2023 1,052 words in the original blog post.
Proxyjacking is a rising cyberthreat that exploits proxyware services to monetize compromised internet-connected devices by illegally selling their IP addresses. This method, discovered by Sysdig's Threat Research Team, involves attackers using vulnerabilities, such as the Log4j, to gain initial access, install an agent, and turn devices into proxy servers, which are then sold for profit. Unlike cryptojacking, which focuses on maximizing CPU usage for cryptocurrency mining, proxyjacking primarily utilizes network resources, making it harder to detect. Although proxyware services like IPRoyal claim ethical operation, the ease and profitability of proxyjacking, combined with the low effort required, make it an attractive option for malicious actors. This poses financial and reputational risks to victims, as they may face increased costs and potential legal issues if their IPs are used in illegal activities. The Sysdig team emphasizes the importance of threat detection and setting billing limits to mitigate these risks.
Apr 04, 2023 2,057 words in the original blog post.
Kubernetes 1.27 introduces a substantial update with 60 enhancements, including new features, improvements on existing ones, and a deprecated feature. A key highlight is the transition of the image registry to a distributed system, enhancing speed and reducing data transfer. Security features have been updated, such as the stabilization of Seccomp by default in kubelet and the evolution of account tokens and admission control rules. Noteworthy is the VolumeGroupSnapshot addition, aiding disaster recovery and forensic investigation. Several "quality-of-life" improvements are also included, such as updating a Pod's resources without restarting it and refining the assignment of internal IPs to services. The release further supports the inclusion of kubectl subcommands via plugins and marks a shift away from dependency on Google Cloud by freezing the k8s.gcr.io image registry. Kubernetes 1.27 is poised to enhance operational efficiency and provide a more robust and flexible platform for users.
Apr 04, 2023 6,375 words in the original blog post.