Home / Companies / Sysdig / Blog / July 2025

July 2025 Summaries

11 posts from Sysdig

Filter
Month: Year:
Post Summaries Back to Blog
Sysdig Secure has introduced a new data security feature that integrates sensitive data discovery into its existing platform, enhancing the ability to detect and prioritize security risks without introducing additional complexity or moving sensitive data out of the cloud environment. By leveraging Bedrock Security's AI-powered classification and detection, sensitive data within cloud storage like S3 buckets can be analyzed in place, with only classification results and metadata sent to Sysdig for further processing. This approach not only maintains data within its original environment but also enriches Sysdig's risk model by correlating data with other security signals such as vulnerabilities and misconfigurations. The feature supports querying through SysQL for automated or custom alerting, allowing security teams to quickly identify and address high-risk resources and streamline policy enforcement. This integration strengthens Sysdig's Cloud Native Application Protection Platform (CNAPP) by providing a comprehensive view of business risk and enhancing compliance capabilities, ultimately aiming to reduce the Mean Time to Remediate (MTTR) for risks associated with sensitive data findings.
Jul 31, 2025 1,128 words in the original blog post.
Sysdig and Semgrep have partnered to create a unified security approach that bridges the gap between runtime and build-time insights, addressing the challenge of effectively resolving security threats in complex cloud environments. This partnership integrates Sysdig's runtime threat detection with Semgrep's static analysis to provide actionable insights by tracing vulnerabilities from production back to their source code, enabling security teams to deliver precise, fixable recommendations to developers. By enhancing communication and collaboration between security and development teams, this integration reduces friction and fosters a security culture rooted in partnership, improving efficiency and prioritization. Ultimately, Sysdig and Semgrep aim to redefine cloud security by moving beyond fragmented tools and noisy alerts to a more cohesive and effective model that enables teams to promptly fix critical issues.
Jul 29, 2025 869 words in the original blog post.
Sysdig and Semgrep have partnered to enhance security operations by bridging the gap between runtime threat detection and static code analysis, offering a unified view of vulnerabilities. This integration leverages Sysdig's runtime threat detection capabilities, powered by Falco, and Semgrep's source context analysis to automatically correlate and enrich security findings with detailed metadata. By embedding Open Container Initiative (OCI) labels into container images during the CI/CD process, the integration creates a persistent link between running containers and their source code, enabling automated data enrichment. This results in a comprehensive remediation ticket that provides both runtime context and source code location, reducing manual correlation efforts and allowing security teams to focus on critical threats while developers receive precise remediation guidance. This approach aims to reduce alert fatigue and decrease Mean Time to Remediation (MTTR), enhancing the overall efficiency of security operations in cloud environments.
Jul 29, 2025 834 words in the original blog post.
Sysdig Secure has introduced a new feature called Data Security Findings, powered by an integration with Bedrock Security, designed to enhance the protection of sensitive data such as personally identifiable information (PII), protected health information (PHI), and financial records. This feature offers continuous scanning and AI-powered fingerprinting to identify and classify sensitive data, helping organizations manage risks and remediate vulnerabilities more effectively. It enables security teams to automatically discover data exposure, prioritize patching and configuration fixes, and visualize sensitive data in attack paths for better threat response. By integrating these capabilities, Sysdig aims to bolster cloud-native cybersecurity, reducing visibility gaps and eliminating tool sprawl, while supporting compliance with regulations like HIPAA, GDPR, and PCI DSS. This initiative is part of Sysdig's broader effort to provide comprehensive security solutions, including Cloud Security Posture Management, Cloud Workload Protection, Cloud Detection and Response, and Vulnerability Management, to help organizations navigate the complexities of cloud environments and protect their data assets more efficiently.
Jul 28, 2025 1,091 words in the original blog post.
Sysdig emphasizes a comprehensive approach to cloud security that balances speed and precision without compromising innovation, advocating for "cloud security, the right way." This involves leveraging agentic AI, open innovation, and runtime insights to provide real-time protection and customizable control. Sysdig's platform features Sysdig Sage, an AI cloud security analyst that understands the business context and guides decision-making, and is built on transparency and community collaboration. The company rejects traditional security methods, focusing instead on dynamic, open-source solutions like Falco for runtime threat detection, aiming to empower developers and security teams with tools that offer clarity, control, and actionable insights. Through its commitment to open innovation and deep system visibility, Sysdig seeks to redefine cloud security by enabling rapid, informed responses to emerging threats while maintaining trust and control over security operations.
Jul 28, 2025 914 words in the original blog post.
The Sysdig Open Source Community has been launched as a platform to foster collaboration and innovation among practitioners, contributors, and students dedicated to enhancing cloud-native security. This community is focused on leveraging open-source projects like Falco, Stratoshark, and sysdig OSS to drive meaningful collaboration, positive security outcomes, and career growth. The forum offers sub-communities for mentorship, job opportunities, and student engagement, alongside events and meetups to encourage real-world connections. It includes activities such as contests, workshops, and webinars to engage participants, and highlights contributions through contests and publications. The community aims to be an inclusive space for software engineers, security professionals, and enthusiasts to share strategies, develop skills, and innovate together in the open-source security landscape.
Jul 28, 2025 1,479 words in the original blog post.
In the rapidly evolving landscape of cloud security, the Sysdig Cloud Defense Report 2025 highlights the integral role of artificial intelligence (AI) both as a tool and a target. The report underscores the widespread adoption of AI, with organizations leveraging Sysdig Sage, an AI-integrated cloud security analyst, to significantly reduce response time to threats. Despite advancements, vulnerabilities such as misconfigurations allow attackers to exploit AI systems, necessitating robust security measures. Runtime visibility emerges as crucial for real-time threat detection, as cloud attacks are increasingly swift, taking place in under 10 minutes. Open source continues to be pivotal in security innovation, with tools like Falco gaining extensive traction. Predictions for the year include persistent targeted attacks and the evolution of AI as a partner in defense, emphasizing the need for a transparent and collaborative approach to cloud security.
Jul 28, 2025 748 words in the original blog post.
Integrating Sysdig with Cortex XSOAR enhances cloud security by providing a unified platform for detection and response, thereby reducing mean time to recovery (MTTR) and addressing threats more efficiently. This collaboration allows security teams to automate incident management processes and execute precise response actions, such as terminating compromised containers or quarantining files, directly at the workload level. The integration can be implemented either through direct connection or by routing data through a Security Information and Event Management (SIEM) system for further enrichment before orchestration by Cortex XSOAR. Sysdig's runtime insights and automated playbooks in XSOAR streamline the response to real-time threats, while the Sysdig content pack in the Cortex XSOAR Marketplace offers pre-built bundles and sample playbooks to aid customization. This setup empowers security teams to handle incidents with agility and confidence, ensuring a comprehensive defense for dynamic cloud environments.
Jul 25, 2025 1,323 words in the original blog post.
Sysdig has launched the Sysdig Open Source Community, a unified hub aimed at enhancing security in rapidly evolving cloud environments through collaboration on open-source projects like Falco, Wireshark, Stratoshark, and sysdig OSS. As AI and container usage surge, security challenges have increased, leading to a greater reliance on open-source tools by companies, including over 60% of the Fortune 500. The community seeks to break down silos by providing a platform for practitioners to collaborate, innovate, and share best practices, offering resources like seminars, job boards, mentoring, and a student support center. With a focus on inclusivity and real-time updates, the community aims to empower engineers, analysts, and students by offering easy access to knowledge, skill validation, and professional opportunities, reinforcing Sysdig's commitment to secure and reliable cloud deployment through open-source collaboration.
Jul 09, 2025 1,250 words in the original blog post.
CVE-2025-53104 is a critical command injection vulnerability discovered by the Sysdig Threat Research Team (TRT) in the GitHub repository gluestack/gluestack-ui, which is used for building React and React Native applications. This vulnerability, with a CVSS v3.1 base score of 9.1, allows attackers to execute arbitrary commands on the GitHub Actions runner by exploiting insecure handling of user-controlled inputs in the discussion-to-slack.yml workflow. This can lead to secret exfiltration and unauthorized modifications of repository content, potentially compromising NPM packages in a supply chain attack. The vulnerability was addressed with a patch released on June 13, 2025, emphasizing the importance of secure input handling and validation in GitHub Actions to prevent such threats.
Jul 07, 2025 899 words in the original blog post.
Model Context Protocol (MCP) server security is vital for AI-driven enterprises due to the unique vulnerabilities it presents as a high-stakes attack surface. Unlike traditional APIs, MCP servers enable autonomous AI agents to execute business processes, which can lead to significant risks if not properly secured. Recent breaches, such as the Sysdig Threat Research Team's discovery of LLMjacking and DeepSeek's database misconfiguration, highlight the susceptibility of MCPs to attacks exploiting the probabilistic nature of AI against legacy security controls. The financial ramifications of such breaches are substantial, with regulatory fines under the EU AI Act and potential customer and stock losses. The structural differences of MCP servers, which often act as the operational backbone for AI, require a new approach to security that includes strong authentication, input validation, granular authorization, and continuous oversight. Organizations must adapt to this new landscape by institutionalizing AI literacy and treating MCP server security as a core component of their business strategy to remain resilient and maintain trust in the age of AI.
Jul 02, 2025 1,150 words in the original blog post.