April 2025 Summaries
17 posts from Sysdig
Filter
Month:
Year:
Post Summaries
Back to Blog
Open source cloud security tools are crucial for organizations striving to maintain security in dynamic, multi-cloud environments by providing transparency, collaboration, and community-driven innovation. These tools, ranging from cloud security posture management to continuous compliance, offer essential solutions for protecting cloud-native infrastructures against evolving threats. Key tools include Open Policy Agent for policy enforcement, Falco for runtime protection, Checkov for infrastructure as code security, Keycloak for identity management, HashiCorp Vault for secrets management, Wazuh for SIEM and log management, Zeek for network visibility, Cloud Security Suite for penetration testing, and OpenSCAP for compliance automation. While open source tools offer cost-effective and flexible security solutions, they require ongoing maintenance and updates, prompting some organizations to consider vendor-managed platforms like Sysdig Secure for a more streamlined approach to cloud security management.
Apr 29, 2025
2,026 words in the original blog post.
In an article published on April 25, 2025, the security company ARMO revealed a method to exploit the io_uring system in Linux to bypass certain security tools, posing a potential threat to systems using tools like Crowdstrike, Microsoft Defender, Falco, and Tetragon. This technique involves using the "curing" tool to exploit the flaw, which allows specific actions to go unnoticed by system call-based security tools, although it requires prior access to the targeted system. In response, Sysdig and Falco have developed detection mechanisms to identify suspicious io_uring activity, with Sysdig releasing a new rule for its users and Falco planning to enhance its detection capabilities later in the week. While io_uring allows asynchronous I/O without traditional system calls, it does not conceal files or processes, and most containerized workloads are unaffected due to default security profiles. A layered defense strategy is recommended to mitigate risks, and Sysdig and Falco are actively working to provide solutions to detect and prevent abuses of the io_uring system.
Apr 25, 2025
833 words in the original blog post.
In a recent episode of the Risky Business "Snake Oilers" podcast, Alex Lawrence, Director of Cloud Security Strategy at Sysdig, discusses with host Patrick Gray the critical need for real-time runtime security in cloud-native environments and how Sysdig is addressing this challenge with innovative solutions. Sysdig is designed for Kubernetes, containers, and cloud-native infrastructure, utilizing system calls instead of traditional network packets to ensure robust security. The company employs eBPF to capture these calls effectively, providing deep visibility through agent-based detection and integrating smoothly into existing DevOps pipelines. Sysdig is often compared to Endpoint Detection and Response (EDR) for Linux, offering essential real-time detection capabilities that are vital for industries like financial services. Furthermore, Sysdig leverages AI through its Sysdig Sage™ assistant, which helps security teams rapidly identify and respond to threats by answering natural language queries, thus enhancing the overall efficiency of security operations in dynamic environments.
Apr 23, 2025
651 words in the original blog post.
CVE-2025-32955 is a vulnerability discovered in the Harden-Runner GitHub Action, a widely used security tool in CI/CD environments, which allowed attackers to bypass its disable-sudo security mechanism, thus enabling them to execute code with elevated privileges undetected. This vulnerability, now patched in version v2.12.0, was found by the Sysdig Threat Research Team and involved exploiting the Linux runner user account's membership in the Docker group, which allowed the execution of privileged operations by restoring the sudoers file. As a result, attackers could disrupt security mechanisms and compromise the integrity and availability of Harden-Runner's protections. Users are advised to update to the latest version to mitigate this risk, as the vulnerability underscores the growing threat of supply chain attacks in modern security frameworks.
Apr 22, 2025
1,373 words in the original blog post.
Sysdig's April 2025 updates introduce several significant enhancements to its platform, notably the expansion of native Windows support in Sysdig Secure, enabling comprehensive security and visibility for hybrid Linux/Windows environments. This update, which includes features like CSPM, vulnerability management, and Windows container image scanning, allows for a unified management approach, reducing the need for separate tools and simplifying security operations. The introduction of Host Shield and Cluster Shield for both Linux and Windows streamlines deployment, reducing operational overhead and facilitating feature access. Additionally, Resource360 and Enhanced Findings Drawers improve investigation efficiency by centralizing relevant information, while Sysdig's LSP integration brings security capabilities directly into developers' code editors, marking a shift towards developer-first security. These updates collectively set a new standard for cloud security by addressing complexity and enhancing DevSecOps operations.
Apr 21, 2025
451 words in the original blog post.
The 555 Benchmark for Cloud Detection and Response is a framework designed to challenge organizations to detect, investigate, and respond to cloud threats within a total of 10 minutes, emphasizing the importance of rapidly addressing potential security breaches to mitigate risks such as financial loss and reputational damage. Sysdig has published two guides to support this initiative: one for cloud security practitioners working in Security Operations Centers (SOCs) and another for CISOs and senior security leaders, highlighting the need for a cultural shift in security mindset alongside technical solutions. These guides encourage collaboration across teams, integration of modern cloud-native tools, and automation of security processes to enhance the speed and effectiveness of threat response. The framework likens organizational security to an orchestra, where harmonious coordination among various roles is essential to achieving seamless threat detection and response, ultimately aiming to modernize and expedite security practices without excessive costs.
Apr 21, 2025
696 words in the original blog post.
On April 15, 2025, the cybersecurity community was jolted by the announcement that the U.S. government would not be renewing its contract with MITRE to manage the Common Vulnerabilities and Exposures (CVE) Program, which MITRE has overseen for 25 years. This sudden development raised concerns about the future of vulnerability tracking, as MITRE plays a crucial role in assigning and managing CVE IDs, working alongside organizations like CISA and Red Hat. However, CISA has temporarily extended MITRE's funding, providing a brief respite, but the contract is set to expire in 11 months, prompting discussions on alternative governance structures for the CVE Program, such as the CVE Foundation. The situation highlights the need for decentralizing vulnerability management and exploring solutions like the EUVD and GCVE, as federal budget cuts and lapsing cyber contracts, including those affecting MS-ISAC and the Election ISAC, create instability in the cybersecurity landscape. Organizations are encouraged to diversify their sources of vulnerability intelligence and strengthen partnerships to ensure resilience in the face of potential changes in the management of cybersecurity vulnerabilities.
Apr 17, 2025
1,146 words in the original blog post.
Kubernetes 1.33 introduces a range of enhancements aimed at improving scalability, security, and usability for cloud-native infrastructure. Key updates include in-place pod vertical scaling, which allows for dynamic CPU and memory adjustments without downtime, and pod generation tracking for improved lifecycle observability and automation. The release also supports the use of OCI artifacts as volume sources, simplifying artifact delivery and supporting modular architecture. Enhancements to service account token configuration enable more granular identity controls, aligning with best practices for multi-tenant security and RBAC. Other updates extend loopback client certificate validity, reducing administrative overhead, and introduce warnings for non-standard IP and CIDR formats to encourage better configuration practices. These changes reflect Kubernetes' ongoing commitment to meeting the evolving needs of engineering and security teams by balancing performance improvements with practical operational benefits.
Apr 16, 2025
1,568 words in the original blog post.
UNC5174, a Chinese state-sponsored threat actor, has been identified by the Sysdig Threat Research Team as using a new open-source tool called VShell in its cyber campaigns, which involve sophisticated techniques like fileless malware and the use of WebSockets for command and control. Previously known for deploying the open-source reverse shell tool SUPERSHELL, UNC5174 now employs VShell, considered superior to the Cobalt Strike framework, to conduct espionage and broker access to compromised environments. The campaign involves using SNOWLIGHT malware to drop a fileless VShell payload, which operates entirely in memory, making it difficult to detect. UNC5174 targets entities in Western countries, including research institutions, government organizations, and critical infrastructure sectors, with their operations blending with non-state-sponsored hackers to complicate attribution. The threat actor's techniques, including phishing, social engineering, and domain squatting, demonstrate advanced capabilities and a focus on remaining under the radar while continuing to support Chinese government objectives.
Apr 15, 2025
4,757 words in the original blog post.
Generative AI (GenAI) is set to transform cloud security posture management (CSPM) by enhancing intelligence, automation, and context in managing cloud risks, allowing security teams to effectively handle misconfigurations and compliance gaps in increasingly complex cloud environments. Traditional CSPM tools primarily scan for vulnerabilities and compliance issues, but GenAI will enable natural language interactions, intelligent alert prioritization, and holistic threat intelligence, streamlining the identification and remediation of cloud risks. By leveraging graph databases, GenAI can map relationships between cloud resources and identify potential attack paths, while also offering predictive analysis for future risks and compliance assistance. Despite concerns about automation, AI-driven CSPM will complement rather than replace human security teams, empowering them to proactively manage and secure cloud infrastructure. Organizations that adopt AI-driven CSPM solutions are expected to stay ahead of emerging threats, marking a paradigm shift towards more proactive and intelligent cloud security.
Apr 14, 2025
1,072 words in the original blog post.
Over the past six years, the Sysdig Agent has evolved from a basic system call sniffer to a comprehensive cyber threat defense mechanism, capable of safeguarding workloads across various environments, including underwater. Initially focused on monitoring Linux hosts and cloud-native environments with tools like Falco, Sysdig shifted towards a security-centric platform, introducing features like runtime threat detection, container image scanning, and Kubernetes security posture management (KSPM) to address sophisticated cyber threats. This transformation was part of a broader industry move towards integrated security solutions known as Cloud-Native Application Protection Platforms (CNAPP), combining runtime security, vulnerability scanning, and posture management. As the Sysdig Agent's capabilities expanded, the associated documentation evolved to simplify user experience by minimizing installation and configuration complexities. This was achieved through the introduction of Host Shield and Cluster Shield components, which streamlined the security offerings and made them more accessible to users. The transition reflects a broader strategy to make cloud security more effective and user-friendly, with the author playing a key role in documenting these changes and analyzing the product's behavior from a user perspective.
Apr 11, 2025
858 words in the original blog post.
Falco Actions, an open-source project, offers real-time monitoring of CI/CD workflows to detect potential threats, leveraging the open-source tool Falco. It has been instrumental in identifying a compromise (CVE-2025-30066) in the GitHub Action tj-actions/changed-files, which affected numerous repositories by using a compromised GitHub Personal Access Token to introduce a payload that could extract secrets from memory. This payload was identified through specific operations involving the proc filesystem to access the memory of the Runner.Worker process. Falco Actions provides detection rules to identify such threats and can be integrated into GitHub workflows to enhance security by tracking runtime activities. The project supports an analyze mode to gather comprehensive information about workflow executions and integrates with external services like VirusTotal and OpenAI to produce detailed reports and remediation options. This incident underscores the growing risk of supply chain attacks in CI/CD environments and the importance of runtime security controls to mitigate potential damage.
Apr 10, 2025
934 words in the original blog post.
Sysdig and Google SecOps have joined forces to address the security challenges faced by Security Operations Centers (SOCs) in cloud environments, where traditional IT security models often fall short. The integration of Sysdig's expertise in cloud-native application protection with Google SecOps' advanced SIEM and SOAR capabilities aims to bridge the gap between DevOps and security teams, providing real-time visibility, risk management, and automated responses. This collaboration enables SOCs to better understand cloud inventories, prioritize risks, and respond swiftly to threats, leveraging tools like YARA-L for advanced threat detection. By optimizing data processing and enhancing the visibility of runtime insights, the partnership reduces costs and improves the security posture of cloud services. The integration empowers SOC teams with comprehensive coverage and automated workflows, ensuring that cloud security operations are both actionable and efficient, thus aligning agility with protection in dynamic cloud environments.
Apr 09, 2025
2,140 words in the original blog post.
Crystal Morin's blog post emphasizes the importance of data-driven metrics, known as Key Risk Indicators (KRIs), for evaluating cloud security and aligning cybersecurity efforts with business objectives. The article outlines five critical benchmarks that Chief Information Security Officers (CISOs) should track: vulnerabilities at runtime, time to investigate, identity governance, infrastructure misconfigurations, and security coverage. These benchmarks provide insights into high-impact risks and help prioritize responses to real-time threats. For instance, CISOs should focus on ensuring that vulnerabilities identified during runtime are addressed, alerts are investigated and responded to quickly, and identity governance adheres to the principle of least privilege. Additionally, infrastructure should be assessed against configuration policies to minimize risks, and security tools should be properly implemented across cloud infrastructure. By continuously monitoring and refining these KRIs, organizations can enhance their cloud security posture, ensuring that their environments are both resilient and aligned with organizational goals, thereby effectively communicating security capabilities to stakeholders.
Apr 08, 2025
1,372 words in the original blog post.
Fast Flux is a technique used by attackers to obfuscate their infrastructure by rapidly changing the IP address a domain resolves to, thus rendering IP blocklists ineffective and complicating efforts to take down malicious servers. The technique involves setting a low Time To Live (TTL) value for DNS records, allowing attackers to frequently change their Command and Control (C2) server's IP address, enhancing the resilience and reliability of their operations. Sysdig Secure detects Fast Flux by employing advanced DNS inspection to identify domains with low TTLs and multiple IP addresses, triggering alerts for potentially malicious activities. While detecting Fast Flux can be challenging due to legitimate use of low TTLs, Sysdig Secure can execute response actions like terminating suspicious processes, although caution is advised to avoid disrupting legitimate functions. Additionally, VirusTotal's Threat Intelligence provides a means to identify suspected Fast Flux domain names by analyzing DNS records and Indicators of Compromise (IoCs). Given that Fast Flux is a feature of the DNS system rather than a bug, a layered defense strategy that includes detection tools and possibly Protective DNS services is critical for prevention. Sysdig Secure, built from a legacy of open-source tools, aims to equip security teams with real-time protection against such cloud threats, supported by the Sysdig Threat Research Team's ongoing intelligence sharing.
Apr 04, 2025
811 words in the original blog post.
Since Falco's graduation from the Cloud Native Computing Foundation (CNCF) in 2024, the open-source security project has experienced significant growth and innovation, as detailed by Loris Degioanni. Falco has achieved 150 million downloads and introduced new technologies like Stratoshark, which combines the capabilities of Falco and Wireshark to enhance system call analysis. Key developments include the creation of Falco Talon, a no-code response engine for Falco events, and the Sysdig Agent for Windows, which extends Falco's detection capabilities to the Windows environment. Falco's plugin ecosystem has grown by 40%, offering expanded integration with third-party services such as Microsoft Entra ID, thereby improving cloud security measures. The introduction of Falco Feeds by Sysdig provides enterprise-grade, expert-written rules, reducing the maintenance burden while maintaining flexibility. Looking forward, Falco aims to deepen Kubernetes integration, enhance automation in runtime security, and create a unified security framework with Stratoshark, setting the stage for a new Kubernetes Detection and Response (KDR) approach that integrates detection, investigation, and response in cloud-native environments.
Apr 02, 2025
1,927 words in the original blog post.
Sysdig and Camptocamp have formed a strategic partnership to enhance cloud security for organizations by combining Sysdig's Cloud-Native Application Protection Platform (CNAPP) with Camptocamp's expertise in open-source IT solutions. The collaboration capitalizes on Sysdig's strengths in real-time threat detection and vulnerability assessment, powered by its Sysdig Secure platform and the open-source Falco tool, while leveraging Camptocamp's extensive market reach and technical consulting skills. This partnership supports a "sell what you use; use what you sell" approach, as Camptocamp integrates Sysdig's solutions into its own hosting platform, thereby gaining practical expertise and credibility. The alliance is aimed at addressing the increasing need for proactive cybersecurity measures in dynamic cloud environments, particularly for sectors with stringent regulatory demands like finance and healthcare. Future plans include further training, joint events, and customer acquisition efforts to meet contemporary security challenges and accelerate digital transformation towards the cloud.
Apr 02, 2025
920 words in the original blog post.