logo

Sysdig Blog

ID: 04fc0b23-8da9-5894-a778-3f49f3c21b14

STIX ID: identity--04fc0b23-8da9-5894-a778-3f49f3c21b14

Feed Type: rss

Earliest post: 2025-03-25

Latest post: 2026-06-03

The Sysdig Blog shares expert insights on cloud-native security, containers, and emerging threats to help teams secure modern infrastructure.

01/01/2020
06/04/2026
Title Date Published Describes IncidentAuthorVisible
Security briefing: May 20262026-06-02TrueTrue
AI agent at the wheel: How an attacker used LLMs to move from a CVE to an internal database in 4 pivots2026-05-26TrueTrue
The expendable extension name: Azure VMAccess naming chaos, password resets, and a detection gap2026-05-20TrueTrue
Agentic AI Tooling: Why Runtime Security Is the Missing Layer2026-05-19TrueTrue
NATS-as-C2: Inside a new technique attackers are using to harvest cloud credentials and AI API keys2026-05-14TrueTrue
CVE-2026-44338: PraisonAI authentication bypass in under 4 hours and the growing trend of rapid exploitation2026-05-12TrueTrue
Dirty Frag (CVE-2026-43284 and CVE-2026-43500): Detecting unpatched local privilege escalation via Linux Kernel ESP and RxRPC2026-05-08TrueTrue
Security briefing: April 20262026-05-05TrueTrue
CVE-2026-31431: “Copy Fail” Linux kernel flaw lets local users gain root in seconds2026-04-30TrueTrue
CVE-2026-42208: Targeted SQL injection against LiteLLM's authentication path discovered 36 hours following vulnerability disclosure2026-04-27TrueTrue
CVE-2026-33626: How attackers exploited LMDeploy LLM Inference Engines in 12 hours2026-04-22TrueTrue
Anthropic Mythos just broke the four-minute mile in cyber offense2026-04-21TrueTrue
CVE-2026-39987 update: How attackers weaponized marimo to deploy a blockchain botnet via HuggingFace2026-04-15TrueTrue
Marimo OSS Python Notebook RCE: From Disclosure to Exploitation in Under 10 Hours2026-04-09TrueTrue
Security briefing: March 20262026-04-06TrueTrue
AI infrastructure security: Why it deserves its own category2026-03-26TrueTrue
AI infrastructure security: Why it deserves its own category2026-03-26TrueTrue
TeamPCP expands: Supply chain compromise spreads from Trivy to Checkmarx GitHub Actions2026-03-23TrueTrue
AI coding agents are running on your machines — Do you know what they're doing?2026-03-23TrueTrue
TeamPCP expands: Supply chain compromise spreads from Trivy to Checkmarx GitHub Actions2026-03-23TrueTrue
AI coding agents are running on your machines — Do you know what they're doing?2026-03-23TrueTrue
CVE-2026-33017: How attackers compromised Langflow AI pipelines in 20 hours2026-03-19TrueTrue
CVE-2026-33017: How attackers compromised Langflow AI pipelines in 20 hours2026-03-19TrueTrue
Detecting CVE-2026-3288 & CVE-2026-24512: Ingress-nginx configuration injection vulnerabilities for Kubernetes2026-03-17TrueTrue
Detecting CVE-2026-3288 & CVE-2026-24512: Ingress-nginx configuration injection vulnerabilities for Kubernetes2026-03-17TrueTrue
Security briefing: February 20262026-03-04TrueTrue
Security briefing: February 20262026-03-04TrueTrue
LLMjacking: From Emerging Threat to Black Market Reality2026-02-24TrueTrue
LLMjacking: From Emerging Threat to Black Market Reality2026-02-24TrueTrue
AI-assisted cloud intrusion achieves admin access in 8 minutes2026-02-03TrueTrue
AI-assisted cloud intrusion achieves admin access in 8 minutes2026-02-03TrueTrue
Security briefing: January 20262026-02-02TrueTrue
Security briefing: January 20262026-02-02TrueTrue
VoidLink threat analysis: Sysdig discovers C2-compiled kernel rootkits2026-01-16TrueTrue
VoidLink threat analysis: Sysdig discovers C2-compiled kernel rootkits2026-01-16TrueTrue
How threat actors are using self-hosted GitHub Actions runners as backdoors2026-01-13TrueTrue
How threat actors are using self-hosted GitHub Actions runners as backdoors2026-01-13TrueTrue
Security briefing: December 20252026-01-06TrueTrue
Security briefing: December 20252026-01-06TrueTrue
EtherRAT dissected: How a React2Shell implant delivers 5 payloads through blockchain C22025-12-16TrueTrue
EtherRAT dissected: How a React2Shell implant delivers 5 payloads through blockchain C22025-12-16TrueTrue
EtherRAT: DPRK uses novel Ethereum implant in React2Shell attacks2025-12-08TrueTrue
EtherRAT: DPRK uses novel Ethereum implant in React2Shell attacks2025-12-08TrueTrue
Detecting React2Shell: The maximum-severity RCE vulnerability affecting React Server Components and Next.js2025-12-05TrueTrue
Detecting React2Shell: The maximum-severity RCE vulnerability affecting React Server Components and Next.js2025-12-05TrueTrue
Security briefing: November 20252025-12-01TrueTrue
Security briefing: November 20252025-12-01TrueTrue
Return of the Shai-Hulud worm affects over 25,000 GitHub repositories2025-11-24TrueTrue
Return of the Shai-Hulud worm affects over 25,000 GitHub repositories2025-11-24TrueTrue
Detecting CVE-2024-1086: The decade-old Linux kernel vulnerability that’s being actively exploited in ransomware campaigns2025-11-20TrueTrue

1–50 of 84