🚨 First confirmed: an AI agent driving container escape and Kubernetes credential replay, no human in the loop.
Same marimo CVE. This time the agent went straight for the container and orchestration plane. Docker socket escape, host credential harvest, full cluster Secret store dumped.
Full research from Sysdig TRT: https://t.co/qNM0Zmll3t
#CloudSecurity #ThreatResearch #AIAgents #KubernetesSecurity
The industry normalized a tradeoff that never should have existed: break least privilege to deploy security.
Sysdig Host Shield Least Privilege Mode removes it. Runtime protection without privileged containers.
Read the blog: https://t.co/KZtgGHRhP7
#CloudSecurity #KubernetesSecurity #RuntimeSecurity #Compliance
The problem with agentic security workflows isn't access to data. It's making that data callable from the agent.
The Sysdig MCP server on AWS Marketplace closes that gap, inside Amazon Bedrock AgentCore.
Read the blog: https://t.co/O1MDfYMDbA
#CloudSecurity #HeadlessCloudSecurity #DSPM #AmazonBedrock
G2 Spring 2026 results are in. Sysdig earned Leader recognition across multiple categories, including CNAPP Leader, Cloud Security Leader, and Customers Love Us. 🏆
See the stories behind the recognition: https://t.co/DEyUvXBYCA
#CloudSecurity#G2Leader#CNAPP
Vulnerability remediation doesn't break down at identification. It breaks down at the handoff.
Sysdig Headless Cloud Security automates the entire workflow, from prioritized finding to developer-ready pull request, in minutes.
Read the blog: https://t.co/rSXgpX2wmJ
#CloudSecurity #HeadlessCloudSecurity #VulnerabilityManagement
The hustle hard era of cloud security is over.
5.5% of production workloads running critical vulns, flat year over year. Attackers exploiting CVEs in under 20 hours.
Sysdig's Crystal Morin on the human ceiling, and what comes next.
Zero Signal podcast: https://t.co/nW3VSXM1Gm
#CloudSecurity #ThreatResearch #AIAgents
Once AI workloads reach production, security becomes an infrastructure and runtime problem, not just a model protection challenge.
The Sysdig team explored NVIDIA's AI stack firsthand to break down what that looks like in practice.
Read the blog: https://t.co/soAJ450WX0
#CloudSecurity #AIWorkloads #RuntimeSecurity #NVIDIA
Sysdig TRT found a detection gap in Azure VM password resets. Microsoft says it's "not a vulnerability." 🚨
Azure allows extension resource names to be user-defined. Activity logs don't include the actual publisher or type. A malicious extension can look like "compliance-check" in your logs.
Full research: https://t.co/qj2XXQyaWm
#CloudSecurity #ThreatResearch #Azure #DetectionEngineering
The bottleneck isn't identifying risk. It's turning requirements into enforceable policy fast enough to matter.
Headless cloud security changes that workflow. Describe the control, Sysdig translates it into validated, deployable policy.
Read the blog: https://t.co/fhYTZmyW0Y
#CloudSecurity #HeadlessCloudSecurity #CSPM
Preventative controls are your pregame strategy. Runtime is where the game is actually played.
Attackers are building working exploits within hours of a CVE dropping. 66% of orgs are running AI workloads on Kubernetes. The attack surface isn't waiting for you.
Read the blog: https://t.co/nBw16JuPw8
#CloudSecurity #RuntimeSecurity #AIWorkloads
Ten years ago, we announced Falco with a simple goal: bring real runtime visibility to cloud-native security. 🎉
175M+ container image pulls. 8,600+ GitHub stars. 1,600+ contributors. What it became is something much bigger.
Watch the full celebration: https://t.co/5o4ZR7SxVd
#Falco #OpenSource #CloudSecurity #CNCF
Massive scale. Traffic surges. No room for guesswork.
See how @SquareEnix uses Sysdig for runtime visibility, faster investigations, and better vulnerability prioritization.
Read the case study: https://t.co/DgjOGuUmdF
3 hours. 44 minutes. That's how long it took for active scanning to start after CVE-2026-44338 dropped.
Advisory-to-exploitation windows are now measured in single-digit hours. Every AI project is a target.
Full research from Sysdig TRT: https://t.co/o3b74QeZXA
#CloudSecurity #ThreatResearch #AIAgents
🚨 NEW: the Sysdig Threat Research Team has identified what appears to be the FIRST published case of a threat actor using a NATS server as command-and-control infrastructure. We’re calling this “NATS-as-C2.”
↳ The full breakdown: https://t.co/iFDL0qCiB8
#CyberSecurity
AI coding agents act with your permissions. But what's actually watching what they do?
Introducing Prempti: open source runtime security for AI coding agents, powered by Falco. Allow, deny, or ask before any action executes.
Learn more: https://t.co/FknJ5ExUGc
#CloudSecurity #OpenSource #Falco #AIAgents
The tools making developers more productive are the same ones being weaponized against them.
@sysdig's @lorisdegio on what AI has done to the speed and scale of attacks, and what defenders need to do about it.
Full conversation: https://t.co/xPBwMUTPAU
#CloudSecurity#AIAgents #CyberSecurity
With public exploit code already available, defenders should assume any local foothold on an unpatched Linux system (including from within a container) can rapidly become root access.
↳ Get the full breakdown:
https://t.co/4KyRADWN1e
We asked @Sysdig moms what their kids think they do for work.
👧 "She talks to Candy Crush."
👦 "She makes sure no one touches computers all day."
👧 "She talks about how to stop bad guys getting in your iPad."
Happy Mother's Day to every mom keeping the cloud safe. 💐
#WomenInSecurity
First CNAPP built natively inside AI coding platforms. Not integrated. Not bolted on. Native.
This is the Sysdig Headless Cloud Security demo you can't miss. 👇
https://t.co/CF7EXOReT8
#CloudSecurity#HeadlessCloudSecurity#CNAPP