Sysdig Sysdig secures cloud innovation with the power of Runtime Insights.

Happy Father's Day to the Sysdig dads. We asked them for their best dad jokes. We regret nothing. πŸ˜…A small sample of the...
06/19/2026

Happy Father's Day to the Sysdig dads. We asked them for their best dad jokes. We regret nothing. πŸ˜…

A small sample of the chaos:

Has anyone seen the cybersecurity team?
All I know is that they ran-som-ware.πŸ˜†

The eye rolls were real. The groans were louder. We loved every second.
Swipe through for the full lineup and drop your favorite dad joke in the comments. You've been warned. 🎨

To all our Sysdig dads: thanks for keeping the cloud secure and the jokes consistently terrible. We wouldn't have it any other way. Happy Father's Day. πŸ’š

06/18/2026

Pods. Isolation. Boundaries that are supposed to hold. πŸ”“

Most people assume containers are sealed off from each other and from the host machine running them. Usually, that's true. But isolation can fail, and when it does, an attacker can move from a single container straight into the host itself.

From there, every other container on that machine becomes fair game.

The cause is rarely anything dramatic. It's something far more ordinary.

Kat breaks down container escapes in under a minute. Watch the full episode. πŸ‘‡

The hustle hard era of security is ending. Not because teams stopped trying, but because the math stopped working.Human ...
06/17/2026

The hustle hard era of security is ending. Not because teams stopped trying, but because the math stopped working.

Human error drives 26% of all data breaches. Threats arrive at machine speed. And any process that requires human input introduces delay, and therefore exploitability.

The shift is already underway. Kill -9 usage rose 140% year over year. Teams aren't just seeing threats. They're acting on them.

We unpacked what that shift actually looks like, and what it means for the humans still in the loop, in our latest article. πŸ‘‡

https://okt.to/xT4Ssz

Stat of the Week: 140% β€” The year-over-year rise in organizations using kill -9 to terminate processes after threat detection. Teams aren't just seeing threats.

06/16/2026

Today, we’re excited to announce Hatem Naguib as Sysdig’s new CEO. πŸŽ‰

Hatem is a proven leader with 35 years of experience building and scaling platforms through some of the biggest shifts in technology. Most recently as CEO of Barracuda, and before that, helping scale VMware’s NSX into a category-defining business.

He joins as AI reshapes how software is built, accelerates the speed and frequency of attacks, and changes how security teams have to operate. It’s the kind of moment that demands both the right security platform and the right leader.

The teams we work with are under more pressure than ever – to move faster with AI and to keep their cloud environments secure while they do.

We recently launched the industry’s first headless cloud security platform, designed to run inside AI coding agents, and Prempti, which brings runtime security directly into the tools developers already use.

Under Hatem’s leadership, we’re building on that momentum to define the next generation of AI-driven cloud security.

Welcome Hatem!

↳ Read the press release: https://okt.to/lF6gXE

🚨 The Sysdig TRT has observed threat actors using CTF framing to trick their own AI assistants into writing attack code,...
06/15/2026

🚨 The Sysdig TRT has observed threat actors using CTF framing to trick their own AI assistants into writing attack code, and then deploying the output as working exploits.🚨

The framing isn't meant to fool defenders. It's meant to fool the attacker's own LLM.

But the jailbreak leaks. The same CTF framing bleeds into every field the model generates, request headers, passwords, IAM session names, API key aliases. Fields a human would never label that way.

πŸ‘€ What the Sysdig TRT observed:
➝ A single source IP hit five separate applications in 18 hours: PraisonAI, LiteLLM, FastGPT, Open-WebUI, and Gotenberg
➝ Multiple independent operators converged on byte-identical CTF framing against the same targets
➝ One actor flipped the technique against a victim's AI agent, using "security canary" language to trick the target's LLM into running a reverse shell

πŸ’₯ Why this matters:
➝ The CTF framing has become a shared jailbreak across unrelated operators
➝ A CVE ID in a User-Agent is now a standalone threat intel signal worth acting on
➝ The leak is consistent enough across 10 source IPs that the framing itself has become a tracking signal

πŸ›‘οΈ What to do:
➝ Flag inbound requests with CVE identifiers in the User-Agent for immediate review
➝ Deploy WAF or IPS rules matching CTF/CVE framing patterns
➝ Sanitize User-Agent, account alias, password, and roleSessionName fields before passing context into any LLM-assisted SOC analysis

🎯 Takeaway:
The CTF framing is not the attack. The attack is underneath it. But it's now consistent enough across unrelated actors that it has become a tracking signal in its own right.

↳ Full research from the Sysdig Threat Research Team: [LINK]

An Anthropic API key has become one of the most powerful credentials in your environment. With it, Claude can reach sens...
06/12/2026

An Anthropic API key has become one of the most powerful credentials in your environment. With it, Claude can reach sensitive data, run code, and act on a user's behalf.

Most security teams still treat it as an afterthought.

That gap matters because the question every security team should be able to answer is simple: when someone uses Claude, can you tell whether the activity is legitimate or the first visible step of a compromise?

For most teams today, the honest answer is no.

Not because the data isn't there. Because a compliance event is one frame, not the whole movie. The context that resolves the ambiguity isn't in the compliance feed. It's in the runtime activity on the same machine, in the moments right before and right after the event.

That's the shift Sysdig's integration with Anthropic delivers. From isolated alert to full runtime context, to machine-speed response.
The credential is new. The discipline is not.

Read the full blog. πŸ‘‡

https://okt.to/vQwR4d

Cloud security isn't just a technical conversation anymore. It's a boardroom one.Sysdig CFO  Walker took that message to...
06/11/2026

Cloud security isn't just a technical conversation anymore. It's a boardroom one.

Sysdig CFO Walker took that message to the Leadership Council's 2026 Spring Leadership Conference in Boston last week. Her keynote covered scaling in the cloud era, navigating cyber risk, and what high-velocity finance looks like when your infrastructure lives in the cloud.

A big thank you to McCullough and the CFO Leadership Council for the platform and the warm reception.

The role of the CFO is evolving fast. The ones leading that change are the ones bringing security, technology, and financial strategy into the same conversation.

Proud of Karen for representing Sysdig on that stage. πŸ’š

In 2018, attackers took nearly a year to weaponize a vulnerability. By 2023, it was eight days. By the end of 2025, hour...
06/10/2026

In 2018, attackers took nearly a year to weaponize a vulnerability. By 2023, it was eight days. By the end of 2025, hours.

That trajectory has one logical endpoint: near real time. πŸ”’

And yet, in-use vulnerabilities have plateaued at 5% for two years running. Teams are prioritizing better. Tools are more mature. Processes have improved. The ceiling hasn't moved.

This is no longer a tooling problem. It's a scale problem.

The window between vulnerability disclosure and active exploit keeps collapsing. Focusing solely on vulnerabilities being actively exploited is no longer enough. And asking humans to move faster isn't the answer either.

The next step isn't more automation. It's a different kind entirely. And the key to making it work is in the guardrails.

Read the full breakdown. πŸ‘‡

https://okt.to/i47pHr

A developer asks an AI agent to refactor a microservice. Seconds later, it's opening files, executing shell commands, an...
06/09/2026

A developer asks an AI agent to refactor a microservice. Seconds later, it's opening files, executing shell commands, and modifying cloud configuration. No human approved any of it. No security tool saw any of it. πŸ”’

Here's the hard truth: traditional behavioral baselines don't work for AI agents. The very actions you want to detect, shell ex*****on, file reads, outbound connections, are the agent's normal operating behavior.

But runtime security isn't useless. The approach just has to change:

πŸ”Ή Known-bad detection catches agents reading SSH keys or connecting to malicious IPs regardless of non-determinism
πŸ”Ή Capability scoping makes the sandbox boundary the baseline
πŸ”Ή Tool-call auditing provides semantic context syscall monitoring alone can't see

Every agent action produces deterministic infrastructure artifacts. Runtime security operates at that layer.

Read the full breakdown. πŸ‘‡

https://okt.to/8zpZXJ

Address

35 Main Street, 21st Floor
San Francisco, CA
94105

Alerts

Be the first to know and let us send you an email when Sysdig posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Share