Skip to content

Company

Sysdig

Sysdig is a cloud security company offering runtime threat detection and vulnerability management for containers, Kubernetes, and cloud infrastructure.

Known aliases

  • sysdig.com
  • Sysdig Inc.
  • Sysdig Threat Research Team
  • Sysdig TRT
  • webflow.sysdig.com

Current stories

security6 publishersConfirmed

Microsoft's 2026 defense report says cross-system intrusions become clearer when signals are joined

Microsoft's 2026 Digital Defense Report says intrusions spanning identity, cloud and supply chains become clearer when defenders join separate signals. Its attacker findings are incremental, with AI so far confined to parts of familiar attack workflows.

Perspective Coverage

7 publishers
Builder
Builder 30%
Operator
Operator 56%
Investor
Investor 14%

Reality

Evidence70
Adoption58
Hype gap+12
Incentives72
Confidence70
security5 publishersConfirmed

Manufacturers selling into the EU now owe ENISA a 24-hour warning on exploited flaws

The Cyber Resilience Act's vulnerability reporting duties are already in force, well before the December 2027 date that governs most of the regulation, and they sit alongside five other disclosure regimes whose clocks start differently.

Publishers:commission.europa.eucsoonline.comdev.toscworld.comwebflow.sysdig.com

Perspective Coverage

5 publishers
Builder
Builder 36%
Operator
Operator 50%
Investor
Investor 14%

Reality

Evidence80
Adoption
Insufficient
Hype gap+15
Incentives55
Confidence72
security6 publishersConfirmed

Storm-3168 mapped an Azure tenant for 17 hours before a seven-minute deletion run

Microsoft says Storm-3168, also tracked as JADEPUFFER, used two stolen Azure service principals to try deleting more than 100 storage accounts. The deletions took about seven minutes, so the 17 hours of API reads before them were when anyone watching those identities had time to act.

Perspective Coverage

6 publishers
Builder
Builder 23%
Operator
Operator 70%
Investor
Investor 7%

Reality

Evidence72
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence70
leadership1 publisherOne report

Triage and tuning decided which SOC caught CISA's red team

CISA's red team breached two critical-sector organisations, and only the water-sector one contained it, isolating machines in up to 20 minutes. The gap traces to alert tuning and triage, so the first fix most SOCs need is analyst time.

Publishers:itpro.com

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives55
Confidence45
security1 publisherOne report

Chainguard discloses 14 Java bugs that were fixed upstream but never got a CVE

Chainguard disclosed 14 Java vulnerabilities that were fixed upstream but never assigned a CVE, one rated critical and one high. Teams still on the affected versions got no scanner alert, some for years, because nobody announced the fixes when they landed at HEAD.

Publishers:chainguard.dev

Reality

Evidence40
Adoption25
Hype gap+10
Incentives75
Confidence45
security3 publishersConfirmed

A hand-debugged Python toolkit turned marimo CVE-2026-39987 into bastion SSH in eight seconds

Sysdig's threat research team watched one operator work a marimo notebook host for nine hours with hand-written scripts, and the eight-second jump to a bastion host at the end ran on tooling already staged on disk.

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 60%
Investor
Investor 7%

Reality

Evidence68
Adoption66
Hype gap+8
Incentives72
Confidence70
security5 publishersConfirmed

CISA now tells critical infrastructure to plant fake credentials for attackers to trip over

The federal cyber agency now recommends planting fake records, credentials and files across critical infrastructure networks, and its pitch to understaffed teams is that an alert on a decoy needs no analyst to interpret it.

Perspective Coverage

5 publishers
Builder
Builder 46%
Operator
Operator 47%
Investor
Investor 7%

Reality

Evidence70
Adoption
Insufficient
Hype gap+15
Incentives30
Confidence75