August 2023 Summaries
7 posts from Sysdig
Filter
Month:
Year:
Post Summaries
Back to Blog
Sysdig's August 2023 update highlights several significant advancements in cloud security and monitoring. The company introduced Sysdig Sage, a generative AI assistant designed to enhance cloud security by employing multi-step reasoning and multi-domain correlation to detect and address risks more effectively. Sysdig has expanded its agentless threat detection capabilities to include GitHub and Okta, allowing for more comprehensive security across different platforms. New permission items, such as Zones and Posture Policies, have been introduced for improved access control, while the Runtime Rule Tuner interface has been simplified for ease of use. Sysdig Monitor has launched Cost Advisor, which offers detailed insights and optimizations for Kubernetes costs, now generally available with enhanced features like private billing and idle cost support. Additionally, Sysdig's new alerting capabilities allow for more precise alert management, including manual resolution and automatic deactivation of orphaned alerts. The update also includes various improvements and enhancements to metrics usage, monitoring integrations, and Sysdig Agents, with support for Control Group v2 and FIPS compliance. The release notes also mention updates to Sysdig's CLI tools, Terraform provider, and integrations with platforms such as Prometheus and Jenkins. Lastly, the update features improvements in Falco's threat detection rules and introduces new resources, blog posts, and educational content to support Sysdig users.
Aug 31, 2023
2,168 words in the original blog post.
The Sysdig Threat Research Team (TRT) uncovered a sophisticated cybercriminal operation named LABRAT, which targets GitLab servers through stealthy cryptojacking and proxyjacking tactics. Differentiating itself from typical attacks, LABRAT employs undetected compiled binaries in Go and .NET, utilizes complex cross-platform malware, and leverages tools like TryCloudFlare to obscure its command and control (C2) infrastructure. The campaign exploits the GitLab vulnerability CVE-2021-22205 to gain access, allowing the attacker to install cryptomining software and use compromised systems for proxyjacking, potentially affecting the reputation and bandwidth of the victims. Furthermore, the attackers employ advanced techniques such as kernel-based rootkits and Global Socket (GSocket) for maintaining backdoor access and evading detection, making it challenging for defenders to identify and mitigate the threat. The operation's financial motivation is clear, but the presence of backdoor access suggests that other malicious activities, like data theft or ransomware, are possible. The continuous updating of tools and tactics by the attackers necessitates constant vigilance and updated threat detection strategies from defenders to effectively counteract and respond to such threats.
Aug 17, 2023
3,706 words in the original blog post.
A recent Freejacking campaign exploiting Google's Vertex AI platform for cryptomining was uncovered by the Sysdig Threat Research Team. Freejacking involves abusing free services for profit, and this campaign utilized free Coursera courses to access Google Cloud Platform (GCP) and Vertex AI without cost to the attacker. The attack was automated, allowing for the creation of numerous instances through fake accounts, which were used to mine the cryptocurrency Dero using GPU resources provided by Vertex AI's Jupyter Notebooks. This process involved launching Tensorflow instances with custom machine types, which were then used to maximize cryptomining efficiency. The attack highlights vulnerabilities in platforms offering free or trial compute services and underscores the importance of robust security measures by both service providers and customers to prevent such abuses.
Aug 14, 2023
967 words in the original blog post.
Cybereason and Sysdig have partnered to enhance security capabilities by integrating Sysdig's cloud threat detection with Cybereason's Extended Detection and Response (XDR) platform, aiming to provide comprehensive protection against cloud-based threats. This collaboration allows Cybereason customers to leverage Sysdig's runtime insights and Falco-powered alerts to identify and respond to cloud and container-related security incidents effectively. The integration addresses the inadequacies of traditional Endpoint Detection and Response (EDR) systems, which often overlook cloud misconfigurations—identified by Gartner as the starting point for 99% of breaches. By incorporating cloud context metadata into Cybereason's XDR platform, the joint solution enriches threat intelligence and correlates it with data from endpoints, networks, and identity sources, offering visual attack narratives and automatic response recommendations. This partnership not only enhances visibility and threat detection but also aims to reduce the mean time to detect and resolve cloud-originated threats, with plans to further integrate additional security insights into Cybereason's Managed Detection and Response services in the future.
Aug 09, 2023
621 words in the original blog post.
Sysdig and Checkmarx have partnered to tackle the overwhelming number of vulnerabilities faced by organizations modernizing cloud applications, by integrating Sysdig's Cloud-Native Application Protection Platform (CNAPP) runtime insights into the Checkmarx One AppSec platform. This collaboration aims to reduce vulnerability noise by up to 95%, allowing developers to prioritize and address critical issues more efficiently. By utilizing Sysdig's ability to identify in-use packages with vulnerabilities and feeding this information into Checkmarx's Software Composition Analysis (SCA), teams can focus on genuine risks, significantly decreasing the workload associated with unnecessary vulnerability remediation. This approach enhances developer productivity, accelerates software delivery, and forms a comprehensive cloud-native security solution from the development stages through to runtime.
Aug 08, 2023
606 words in the original blog post.
The 2023 Global Cloud Threat Report by the Sysdig Threat Research Team reveals the rapid pace and sophistication of cloud-based cyberattacks, highlighting that attackers are leveraging the complexity of cloud environments to evade detection and execute swift attacks. The report emphasizes the growing prevalence of cryptojacking, where attackers exploit cloud and container environments for cryptomining, causing financial losses for victims. It also discusses the security challenges in the software supply chain, revealing how malicious containers in public image repositories have been used for distributed denial of service campaigns, particularly in geopolitical conflicts like Russia's invasion of Ukraine. The telecommunications and financial sectors are identified as primary targets, with attackers using automation and stealth tactics, such as IP obfuscation and privilege escalation via AWS CloudFormation, to navigate cloud environments without detection. The research highlights the importance of runtime security controls, as traditional static analysis and vulnerability scanning miss a significant portion of malicious images. Additionally, the report suggests that as cloud-native tools and applications become central to networks and security, supply chain compromises will remain a critical focus for both attackers and defenders.
Aug 02, 2023
966 words in the original blog post.
CVSS Version 4.0 introduces significant changes to enhance the accuracy and granularity of vulnerability scoring, with a focus on integrating environmental and threat metrics for a more comprehensive risk assessment. The new version includes added Base Metrics and Values, replacing the Scope metric with Impact Metrics that evaluate effects on both vulnerable and subsequent systems, and the inclusion of a Supplemental Metric Group offering additional context for remediation prioritization. The Attack Requirements metric further refines scoring by accounting for specific conditions needed for attack execution, as illustrated by the "Dirty COW" vulnerability example. Moreover, the revised Threat Metric Group, formerly known as Temporal Score, simplifies assessment with a singular focus on Exploit Maturity, while environmental metrics allow for customization based on unique operational contexts. This update aims to align vulnerability management more closely with organizational risk management processes, encouraging vendors to adopt these metrics into their solutions for tailored risk assessments.
Aug 01, 2023
1,804 words in the original blog post.