logo

Threat hunting with Sysdig: Uncovering “IngressNightmare”

ID: 30580a16-2483-519b-92ea-b6f224b4729c

STIX ID: report--30580a16-2483-519b-92ea-b6f224b4729c

Feed Name: Sysdig Blog

Threat Score
88/100

Date Published: 2025-08-06

Date Updated: 2026-05-01

...
...

This Sysdig blog post details the IngressNightmare zero-day (CVE-2025-1974) that impacted an estimated 40% of Kubernetes environments using the NGINX Ingress Controller, describes observed in-the-wild exploitation enabling RCE and shell access, and explains how Sysdig’s runtime detections, threat intelligence feeds, graph search, and automated response/remediation capabilities help detect, contain, and remediate affected workloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.