June 2025 Summaries
14 posts from Sysdig
Filter
Month:
Year:
Post Summaries
Back to Blog
Sysdig's June 2025 updates focus on enhancing AI-driven security insights, threat management, and incident response, aiming to simplify and streamline security operations across multi-cloud and Kubernetes environments. The introduction of Sysdig Sage for Search allows users to ask security-related questions in plain language, converting them into SysQL queries, thereby simplifying security workflows and offering improved visibility across major cloud platforms. The new "Threats" capability consolidates related security signals into single, actionable incidents, reducing alert fatigue and enabling faster decision-making through AI-enriched summaries. Additionally, Sysdig now allows manual execution of response actions, such as isolating compromised containers, to provide security teams with immediate reactive capabilities. Support for Amazon Bedrock has been introduced, allowing organizations to apply security practices to AI workloads and ensure compliance with regulatory requirements. Furthermore, the new Automations feature enables custom response workflows for critical events, reducing manual effort and supporting efficient threat management and governance across complex environments.
Jun 26, 2025
968 words in the original blog post.
Sysdig Sage is an AI-powered cloud security analyst that enhances cloud-native application protection by assisting teams in managing complex and dynamic security threats. Utilizing generative AI, Sysdig Sage provides rapid identification, investigation, and response to threats across cloud security posture management, vulnerability management, and cloud detection and response. The platform employs AI-powered graph search to convert natural language queries into actionable insights and offers intelligent vulnerability remediation by providing clear, step-by-step instructions for addressing vulnerabilities without disrupting applications. By streamlining threat response and reducing remediation times, Sysdig Sage enables security teams to act swiftly and confidently, functioning as a virtual security teammate that enhances existing resources without requiring additional personnel.
Jun 25, 2025
1,045 words in the original blog post.
Sysdig Sage is an AI-based graph search assistant designed to enhance cybersecurity by simplifying how professionals interact with and extract insights from complex security data. It builds on Sysdig's AI capabilities, initially launched for cloud detection and response, by introducing a search engine that enables users to pose questions in natural language, which are translated into SysQL queries against a graph-based datastore. This assists security teams in exploring relationships, entities, and events without requiring knowledge of query syntax, thus accelerating workflows like incident response and policy validation. SysQL, a proprietary query language, is tailored specifically for cybersecurity, allowing for efficient cloud and Kubernetes resource queries and security analysis. The system incorporates a fine-tuned large language model (LLM) that interprets user intent and generates structured queries, enhancing precision and relevance. Sysdig Sage's inference pipeline leverages both the LLM and a cybersecurity knowledge graph to handle complex queries and ensure accuracy through iterative refinement, making the tool robust, adaptable, and seamlessly integrated into Sysdig's platform. This enables security teams to obtain actionable insights without needing to learn complex query languages, ultimately transforming how they approach cloud and Kubernetes resource inspection, vulnerability triage, and security posture monitoring.
Jun 24, 2025
2,711 words in the original blog post.
In the wake of the June 22, 2025, U.S. strikes on Iranian nuclear sites, the Sysdig Threat Research Team anticipates heightened cyber activities from Iranian state-sponsored groups and hacktivists, comparable to the cyber incidents at the Russia-Ukraine war's onset in 2022. The bulletin provides security teams with forward-looking guidance and threat intelligence to prepare for potential attacks, highlighting the tactics and tools used by key Iranian cyber groups. Notably, APT35 targets credentials from platforms like Microsoft 365 and Gmail, employing tools such as Hyperscrape and developing malware like PowerLess and BellaCiao. APT33 is known for its cloud-first intrusions and social engineering via LinkedIn, while Pioneer Kitten collaborates with ransomware gangs, exploiting VPN and network device vulnerabilities. Recommendations include enforcing multi-factor authentication, monitoring for unauthorized security tool usage, and ensuring backup integrity to mitigate ransomware threats.
Jun 23, 2025
1,060 words in the original blog post.
Security teams face an overwhelming number of vulnerability alerts, with prioritization tools often leaving them with a lengthy list of issues and little guidance on subsequent actions. While prioritization helps highlight which vulnerabilities require immediate attention, turning insights into effective remediation remains challenging due to misalignment between security and development teams, who operate on different timelines and have varying priorities. To address these challenges, organizations must focus on effective remediation strategies, such as identifying impactful fixes, providing clear instructions, reducing repetitive work, and automating workflows. The use of AI-driven tools can facilitate this process by offering low-friction solutions and structured guidance to developers, thus improving collaboration and accelerating the closure of critical vulnerabilities. Sysdig exemplifies this approach by integrating runtime context with AI-powered remediation guidance, which helps teams close the gap between risk identification and resolution, ultimately fostering stronger team alignment and delivering measurable outcomes in vulnerability management.
Jun 23, 2025
741 words in the original blog post.
The Sysdig Threat Research Team (TRT) identified critical security vulnerabilities in GitHub Actions workflows across various high-profile open source projects, such as those maintained by MITRE, Splunk, and the Spotipy Python library. These vulnerabilities primarily revolve around the misuse of the pull_request_target event, which can expose repository secrets and grant high-privilege access to attackers when handling pull requests from untrusted sources. Despite the availability of well-documented methods for securing CI/CD workflows, many projects remain susceptible due to a lack of maturity in implementing security best practices. The article highlights specific instances where these vulnerabilities were exploited to exfiltrate secrets, and it offers recommendations for mitigating such risks, including splitting workflows into privileged and unprivileged components, restricting GITHUB_TOKEN permissions, and using runtime threat detection tools like Falco Actions. The Sysdig TRT continues to collaborate with affected organizations to address these issues and improve the security posture of open source projects.
Jun 17, 2025
2,403 words in the original blog post.
Falco, a CNCF graduated runtime security project, is now available as an AWS-validated Amazon EKS add-on, simplifying runtime security deployment for Amazon Elastic Kubernetes Service (EKS) users. This integration allows for single-command installation, automatic updates, and seamless AWS service integration, enhancing cloud-native security by monitoring system calls at the kernel level to detect threats in real-time. The add-on ensures consistent deployment across multiple EKS clusters, avoiding configuration drift, while also providing automated lifecycle management. Users can customize Falco rules using ConfigMaps to tailor security policies according to their workload patterns, and security events can be integrated with Amazon CloudWatch for monitoring. The project invites community participation through its open-source nature, allowing contributions to rule sets and community interaction via Slack and GitHub.
Jun 17, 2025
1,240 words in the original blog post.
Sysdig has introduced new intelligent vulnerability remediation capabilities powered by its AI cloud security analyst, Sysdig Sage, to enhance cloud security management. These capabilities allow security teams to transition from merely identifying vulnerabilities to effectively resolving them by providing actionable recommendations that prioritize risk reduction without disrupting application dependencies. The system offers a flexible view of vulnerability data, allowing users to filter findings by key risk factors and focus on the most impactful resolutions. Sysdig Sage provides step-by-step remediation instructions in natural language, enabling engineering teams to implement fixes efficiently, reducing the attack surface with minimal friction. This upgrade aims to empower organizations to move beyond basic prioritization and take meaningful action, ultimately saving time and proving impact through effective vulnerability management.
Jun 16, 2025
701 words in the original blog post.
Sysdig has introduced a significant update to its vulnerability management solution, focusing on accelerating vulnerability remediation at the source by integrating AI and runtime context. The new features, powered by Sysdig Sage, an AI cloud security assistant, provide security teams with actionable guidance and automated analysis to prioritize and remediate vulnerabilities efficiently. This approach enables teams to focus on high-impact fixes and reduces the time spent on repetitive patching, ultimately improving security posture. By emphasizing remediation over mere prioritization, Sysdig aims to bridge the gap between security and development teams, ensuring vulnerabilities are addressed quickly and effectively. The solution leverages deep runtime insights and intelligent recommendations to empower teams to manage known vulnerabilities with available fixes, moving beyond traditional alert-based systems to achieve measurable risk reduction.
Jun 16, 2025
1,169 words in the original blog post.
Cloud security strategies must evolve to prioritize runtime security due to the dynamic and ephemeral nature of cloud-native environments. Traditional tools like Cloud Security Posture Management (CSPM) and Endpoint Detection and Response (EDR) fall short in real-time threat detection, as they were not designed to handle the rapid changes and complexities of cloud infrastructures. Runtime security, on the other hand, offers continuous monitoring and automated responses to live threats, effectively reducing detection and response times from hours or days to mere minutes. This approach not only improves the mean time to detect (MTTD) and mean time to respond (MTTR) but also reduces costs associated with breach recovery by addressing threats as they occur. While posture management remains important, it should complement, rather than lead, a robust cloud security strategy that adapts to the fast-paced cloud environment.
Jun 13, 2025
928 words in the original blog post.
In a rapidly evolving Kubernetes landscape, managing security across clusters is increasingly challenging due to factors such as multi-cloud setups, edge deployments, and stringent compliance requirements. Kubectl plugins, which are command-line extensions for the standard kubectl tool, offer security teams enhanced functionality to address these challenges by enabling faster detection of misconfigurations and threats. These plugins allow users to audit permissions, trace network activity, manage secrets, and streamline incident response, making them essential tools for maintaining security without hindering development speed. However, careful consideration is necessary when choosing plugins, as not all are regularly maintained or officially audited, and they may require access to sensitive data. The article highlights the top kubectl plugins for 2025, which range from tools for visualizing RBAC permissions to capturing network packets, thus empowering security engineers with greater visibility and control over their Kubernetes environments.
Jun 11, 2025
2,395 words in the original blog post.
As artificial intelligence (AI) becomes increasingly prevalent, ensuring robust AI security in multi-cloud environments is crucial for organizations seeking a competitive edge. Companies face challenges such as limited visibility, regulatory compliance, and evolving threats across various AI implementation models, including cloud platforms and on-premises systems. To address these issues, a strong security foundation is essential, incorporating continuous monitoring, risk management, and behavior-based threat detection. Tools like Sysdig, powered by Falco, provide real-time monitoring and threat detection by leveraging managed rules and cloud audit logs, allowing companies to identify and address vulnerabilities efficiently. Establishing a security posture management (AI-SPM) strategy helps organizations meet regulatory standards, such as the EU AI Act and NIST AI Risk, and build trust with customers. By adopting a structured approach to AI security and leveraging advanced threat detection tools, organizations can safeguard their AI infrastructure against sophisticated attacks and maintain compliance with rapidly evolving regulations.
Jun 04, 2025
1,399 words in the original blog post.
Vulnerability management (VM) is evolving to address the challenges of alert fatigue, prioritization issues, and the dynamic nature of cloud-native environments. Traditional VM tools struggle to keep up with the fast-paced, distributed infrastructures of modern architectures like Kubernetes and serverless systems. The text outlines a new approach to VM that emphasizes comprehensive scanning for total visibility, smarter prioritization that focuses on exploitable vulnerabilities, and automated remediation to quickly address threats. By integrating these strategies, security teams can shift from a reactive to a proactive stance, managing risks with greater precision and confidence. The document encourages a unified approach among development, security, and operations teams to ensure clear communication and accountability, ultimately transforming vulnerability management from a chaotic process into a more controlled and effective operation.
Jun 03, 2025
1,081 words in the original blog post.
A recent attack exploited a misconfigured system hosting Open WebUI, an AI interface for enhancing large language models (LLMs), allowing a threat actor to inject and execute malicious AI-generated code. The attacker uploaded a sophisticated Python script, leveraging Open WebUI's tool system to run cryptomining software on both Linux and Windows platforms while employing uncommon methods for defense evasion, including processhider and argvhider tools. A Discord webhook was used for command and control, highlighting the growing use of AI in developing malware. Sysdig Threat Research Team detected the attack, emphasizing the importance of runtime security and multi-layer threat detection to counteract such complex threats. The incident underscores the risks associated with exposing systems like Open WebUI to the internet without proper configuration and authentication, as attackers continuously scan for such vulnerabilities.
Jun 02, 2025
2,371 words in the original blog post.