惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hacker News - Newest:
Hacker News - Newest: "LLM"
The Last Watchdog
The Last Watchdog
L
LINUX DO - 最新话题
Application and Cybersecurity Blog
Application and Cybersecurity Blog
T
Troy Hunt's Blog
Cloudbric
Cloudbric
N
News | PayPal Newsroom
Security Archives - TechRepublic
Security Archives - TechRepublic
TaoSecurity Blog
TaoSecurity Blog
H
Hacker News: Front Page
Help Net Security
Help Net Security
S
Secure Thoughts
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
PCI Perspectives
PCI Perspectives
AI
AI
Hacker News: Ask HN
Hacker News: Ask HN
NISL@THU
NISL@THU
Last Week in AI
Last Week in AI
Forbes - Security
Forbes - Security
The GitHub Blog
The GitHub Blog
D
DataBreaches.Net
Scott Helme
Scott Helme
Jina AI
Jina AI
T
Threatpost
W
WeLiveSecurity
P
Palo Alto Networks Blog
F
Fortinet All Blogs
腾讯CDC
人人都是产品经理
人人都是产品经理
云风的 BLOG
云风的 BLOG
博客园 - 【当耐特】
Apple Machine Learning Research
Apple Machine Learning Research
P
Privacy International News Feed
P
Proofpoint News Feed
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
A
About on SuperTechFans
V
Vulnerabilities – Threatpost
www.infosecurity-magazine.com
www.infosecurity-magazine.com
C
Cyber Attacks, Cyber Crime and Cyber Security
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
D
Darknet – Hacking Tools, Hacker News & Cyber Security
IT之家
IT之家
美团技术团队
I
InfoQ
阮一峰的网络日志
阮一峰的网络日志
T
Threat Research - Cisco Blogs
博客园 - 司徒正美

Sysdig Blog

CVE-2026-39987 update: How attackers weaponized marimo to deploy a blockchain botnet via HuggingFace Kubernetes 1.36 - New security features 5 steps to securing AI workloads Marimo OSS Python Notebook RCE: From Disclosure to Exploitation in Under 10 Hours Security briefing: March 2026 The Sysdig MCP server is now available in AWS Marketplace Risk isn’t reduced until you take action: How teams resolve issues in the cloud AI infrastructure security: Why it deserves its own category Three pillars for building effective runtime-powered cloud defense, the right way Closing the cloud security gap with runtime security Seeing risk isn’t stopping it: Why visibility alone isn’t enough TeamPCP expands: Supply chain compromise spreads from Trivy to Checkmarx GitHub Actions AI coding agents are running on your machines — Do you know what they're doing? Runtime security for AI coding agents: Protecting AI-assisted development How runtime insights power every cloud security use case CVE-2026-33017: How attackers compromised Langflow AI pipelines in 20 hours Inline Cloud Response: Accelerating AWS threat containment for SOC teams Runtime malware detection for AWS Fargate Detecting CVE-2026-3288 & CVE-2026-24512: Ingress-nginx configuration injection vulnerabilities for Kubernetes Malware detection with Sysdig Security briefing: February 2026 Leveling up Kubernetes Posture: From baselines to risk-aware admission Eliminating runtime blind spots: How CleanStart and Sysdig build continuous trust across the container lifecycle LLMjacking: From Emerging Threat to Black Market Reality Real risks live at runtime: Why CISOs must care about deep telemetry in 2026 Sysdig named a Leader in the Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 How to run rootless containers AI-assisted cloud intrusion achieves admin access in 8 minutes Security briefing: January 2026 Securing GPU-accelerated AI workloads in Oracle Kubernetes Engine Bringing OSS runtime security to AWS: Falco integration with AWS Security Hub CSPM Our customers have spoken: Sysdig rated a Strong Performer in Gartner® Voice of the Customer for Cloud-Native Application Protection Platforms Protecting sensitive business data in preparation for the organization's Gen AI VoidLink threat analysis: Sysdig discovers C2-compiled kernel rootkits AI is still a workload: A practical guide to securing AI workloads How threat actors are using self-hosted GitHub Actions runners as backdoors How Sysdig Sage delivers AI-powered, real-world vulnerability management Security briefing: December 2025 Top 10 ways to get breached in 2026 EtherRAT dissected: How a React2Shell implant delivers 5 payloads through blockchain C2 Introducing runtime file integrity monitoring and response with Sysdig FIM How to detect multi-stage attacks with runtime behavioral analytics EtherRAT: DPRK uses novel Ethereum implant in React2Shell attacks Detecting React2Shell: The maximum-severity RCE vulnerability affecting React Server Components and Next.js The rise of AI agents: How autonomous AI Is transforming cloud security Kubernetes 1.35 - New security features The Urgency of Securing AI Workloads for CISOs Security briefing: November 2025 Quantum and the cloud: Science fiction turned security strategy Cloud security, the right way: What the industry should demand (and why "good enough" isn't) Return of the Shai-Hulud worm affects over 25,000 GitHub repositories Detecting CVE-2024-1086: The decade-old Linux kernel vulnerability that’s being actively exploited in ransomware campaigns What’s old is new again: How to demystify AI security with AIBOMs Securing Kubernetes with agentic cloud security How agentic cloud security reduces real risks Hunting reverse shells: How the Sysdig Threat Research Team builds smarter detection rules Shifting left with AI and MCP: Sysdig + Amazon Q Developer How Falco and Stratoshark close the gap between open source runtime detection and deep forensic analysis Investigating security issues with ChatGPT and the GitHub MCP server New runc vulnerabilities allow container escape: CVE-2025-31133, CVE-2025-52565, CVE-2025-52881 Harden your LLM security with OWASP Security briefing: October 2025 How agentic AI is changing cloud security Kubernetes Incident Response: Detect, investigate, and contain in under 10 minutes Sysdig recognized as a Cloud Security Leader in Latio Tech Cloud Security Market Report AI echolocation of cloud risks using Sysdig & Snyk MCP servers Sysdig MCP Server: Bridging AI and cloud security insights Understanding CVE-2025-49844: “RediShell” Critical Remote Code Execution in Redis How Sysdig secures your containers and Kubernetes Sysdig Security Briefing: September 2025 Cloud security, the right way: The 3 pillars of real-time defense Open source spotlight: Bringing web application security to Falco with Falcoya's Nginx plugin Malicious NPM packages: Are you exposed? AI for SOC teams: 5 cloud security prompts to start your day with Sysdig Sage™ Shai-Hulud: The novel self-replicating worm infecting hundreds of NPM packages ZynorRAT technical analysis: Reverse engineering a novel, Turkish Go-based RAT Modern vulnerability management, built for the cloud Build your AWS incident response playbook with open source tools 2025 Gartner® CNAPP Market Guide: Runtime visibility is no longer optional Threat hunting with Sysdig: Uncovering “IngressNightmare” Open source spotlight: From alerts to action with AI-powered Falco Vanguard From triage to action: How Sysdig’s agentic cloud security platform slashes noise and accelerates remediation The vision comes to life: Agentic cloud security with Sysdig Sage™ Data security findings: A technical deep dive Connecting runtime to source: Sysdig and Semgrep integration Fix what matters, faster: How Sysdig and Semgrep are unifying security without silos – from code to runtime Defending sensitive data with Sysdig Secure Redefining cloud security, the right way Join the movement: The Sysdig Open Source Community is live A smarter, safer cloud in the age of AI Unifying detection and response: Sysdig + Cortex XSOAR for security at cloud speed The future of security is open, and it needs a unified hub: The Sysdig Open Source Community is here CVE-2025-53104: Command injection via GitHub Actions workflow in gluestack-ui Why MCP server security is critical for AI-driven enterprises What’s new in Sysdig — June 2025 AI-powered CNAPP with Sysdig Sage™ Revolutionizing Cybersecurity Search with Sysdig Sage™ Sysdig Threat Bulletin: Iranian Cyber Threats The end of the prioritization-only era: Vulnerability management needs action Dangerous by default: Insecure GitHub Actions found in MITRE, Splunk, and other open source repositories
Masterclass: AI is more than ChatGPT and LLMs
Sysdig Team · 2026-04-15 · via Sysdig Blog

Artificial intelligence is trendy, and it seems like it’s everything tech companies talk about.

It also seems like it’s something completely new.

However, AI has been around as an academic discipline since 1956, and it was already beating chess masters by the 90s. What we understand as AI today is generative AI, a technological breakthrough that can solve general-purpose problems rather than specific ones. Nevertheless, generative AI is only a drop in the ocean of artificial intelligence, and it’s not a silver bullet.

This article was written from the knowledge of multiple AI and security experts across Sysdig. From them, you will get an overview of the AI landscape, evaluate some cases where AI and security go hand in hand, and discover how you can create your own neural network with just a spreadsheet.

This article is part of a series on AI and security:

AI used to be complex algorithms

By Crystal Morin, Senior Cybersecurity Strategist

We consider artificial intelligence any complex calculation that performs a task simulating human intelligence.

Under this definition, some bulky spreadsheets could be considered artificial intelligence, and I find it wonderfully demystifying. We’ll get back to this thought later.

On a more serious note, we can find early AIs in video games. The algorithm that moves enemies across the screen, finds paths to positions, and adds personality is artificial intelligence.

By February 1997, IBM’s Deep Blue managed to beat Garry Kasparov, a reigning world champion, in some chess games. Achieving this was more nuanced than simply querying a database of all possible outcomes and choosing the best one. While Deep Blue evaluated 200 million chess positions per second, it also considered other parameters, such as how important it was to keep the king in a safe position.

Deep Blue heralded an era of complex algorithms that are still used in video games, in manufacturing to anticipate production errors, or in logistics to plan transport routes.

AI is now based on statistics: Fuzzy logic and Bayesian math

By Alejandro Villanueva, Sr. Staff Product Manager

Our brain works with fuzzy logic rather than complex algorithms. Life is not black and white, 0 or 1, to our brain. For us, the inputs and outputs are unclear.

We cannot even agree on what green and blue are. Check out “Is My Blue Your Blue” as an indicator. I consider colors bluer than the rest of the population:

We don’t care if what we see is a tiger. We’ll run first, and we’ll re-evaluate once we are safe. To survive, we need to be good at learning patterns and identifying outliers.

Computers can replicate this fuzziness using statistics, and Bayesian programming was among the first techniques for that.

Statistics in cybersecurity

By Miguel Hernández, Sr. Threat Research Engineer

For example, a Bayesian spam filter learns the probable distribution of words, or a combination of words, present in junk mail. When given a completely new email, the filter scores the probability that it is spam.

Security tools like SIEMs and antivirus software use statistics to profile a system’s typical behavior and then identify abnormal behavior. These profiles can be based on the list of processes to flag a malicious binary; on metrics to detect resource usage spikes; or on resource access to highlight suspicious network connections or file access.

While early security technologies relied on relatively simple statistical models, current solutions increasingly use neural networks to model complex, high-dimensional data. This evolution enables more accurate detection of previously unseen threats and demonstrates how statistical learning remains the foundation of AI-driven cybersecurity.

The curse of AI’s moving target

By Mateo Burillo, Product Manager

Deep Blue was a huge milestone back in the day; it was a wake-up call for many people. Suddenly, the Isaac Asimov books and movies like RoboCop were coming true.

However, reality soon followed.

We now see how complex algorithms and Bayesian programming are too simple and can only be used to solve concrete problems.

So we stopped considering them artificial intelligence, at least academically.

This is AI’s curse: the more we understand our brain, the more computing advances, the more strict we are in labeling something as AI.

So, where are we now?

It’s all about neural networks

By Víctor Jiménez, Content Contributor.

If you want to succeed at simulating human thinking, you have to take some inspiration from biology.

For example, a neural network uses math to model the way neurons interconnect in our brains:

  • They are composed of nodes organized in layers.
  • The value of each node is a weighted sum of the values from the nodes on the previous layer.
  • The first layer is formed by the network's inputs, and the last layer represents the outputs.

It really is as simple as a bunch of additions and multiplications. But it’s such an abstract concept that it’s not easy to see how to put it into practice.

So, I prepared a very simple neural network that can detect the digits 0, 1, and 8 on a seven-segment display. To demonstrate how simple all this math is, I did it using a simple spreadsheet that you can download and play around with.

Here is a quick guide so you can inspect the spreadsheet at your own pace:

  • The inputs, A to G, are 0 or 1 values indicating whether a given segment on the display is illuminated.
  • The hidden layer is used to identify specific features:
    • The first node detects a stick by assigning weights to segments A, B, and C, while ignoring the remaining inputs.
    • The second node detects the remaining peripheral segments.
    • The third node detects the middle dash.
  • The output combines these features to identify what number is showing:
    • It’s a Zero if it contains the stick and the peripheral segments, but not the dash.

Again, it doesn’t get much more complicated than these additions and multiplications (kind of). The main difference from a proper neural network is the volume of nodes, which can be in the millions.

Note: This math (matrix multiplication and addition) is the same as that used in 3D graphics. That’s why graphic cards are also used for AI computing.

If you want to see a more realistic example, check out this neural network simulator that can detect handwritten numbers. There are plenty of tutorials on building a neural network to classify handwritten numbers and training it on the MNIST original dataset.

Wait, train it?

Machine learning: Training neural networks

By Emanuela Zaccone, AI Staff Product Manager

This structure of nodes and weights is called a neural model. The model we used for our digit detector was relatively simple, and we could manually assign the weights.

However, how do you build a model with billions of nodes?

Well, you train it.

One way to do it is with genetic algorithms:

  1. Start with a network structure.
  2. Define a scoring metric to evaluate the model’s performance. We’ll call that the fitness function.
  3. Provide some random weights and run a simulation.
  4. Use the fitness function to pick the most successful models from this generation.
  5. Vary the node values slightly and run another simulation.
  6. Pick the most successful ones, vary slightly, simulate again, and repeat hundreds of times.

If you are lucky, after several generations, you’ll end up with a model that can perform the task you are asking it to do. This system is inspired by how natural selection chooses the fittest organisms and represents the trial-and-error process we humans use to learn.

Note that this training method is not the most optimal, so it’s not exactly how AI models are trained. In any case, take it as an example of a way a computer can learn. Genetic algorithms also make for very entertaining content.

Until recently, the most significant area to which machine learning has been applied is computer vision, where AI models can recognize objects in images.

Robots and self-driving cars use computer vision to navigate; your phone’s camera uses it to adjust settings based on what you are photographing; and factories can detect failures before they leave the production line.

It also plays a significant role in modern medicine as an aid in diagnostics. For example, it helps detect autoimmune diseases from photos of your nails.

Neural networks are being used everywhere, from reducing noise in your microphone so your video calls sound better, to aiding in industrial design to create better rocket engines.

Neural networks in cybersecurity

By Crystal Morin, Senior Cybersecurity Strategist

As we mentioned earlier, modern spam filters and profilers use neural networks.

The use of neural networks allows profilers to process data from several sources. For example, banks often feed all your activity to a neural network to flag suspicious activity.

However, it’s been challenging to build accurate, single-purpose neural networks for cybersecurity. Technology changes too often, and it’s almost impossible to debug a model.

That’s why security applications for these models are mostly limited to computer vision and biometrics, such as fingerprint sensors, facial recognition, and security cameras.

A new cybersecurity area born with neural networks is adversarial training. It studies dark AI attacks on models like evasion or data poisoning, and the defenses against such attacks. In 2017 these kinds of attacks became popular when security researchers tricked self-driving cars into speeding up by modifying traffic signals.

Generative AI: LLMs and diffusion

By Manuel Boira, Senior Solutions Architect

But the current AI hype has nothing to do with the above. What everyone knows about artificial intelligence nowadays is generative AI: algorithms capable of generating content, like text (with large language models) or images (with diffusion models).

These are still neural networks at their core, with some added bells and whistles.

Creating a large language model

To simplify, a large language model (LLM) starts as a neural network trained to predict the next word in a text. Similar to the predictive text in your phone’s keyboard.

It’s trained on as much written text as possible, and that text is tagged with some context so the AI can understand the difference between languages and between formal and technical expressions.

At this stage, the AI is scored positively if it can reproduce existing texts.

But as we learned from the “write a paragraph with predictive text only” experiment, this leads to an AI that generates only nonsense.

In a second training round, we refine the model.

To that end, we use a different LLM to score the generated text and ensure it aligns with our guardrails and biases. Errors at this stage can lead to surprising results, such as a version of GPT-2 becoming lewd due to an error in the scoring function.

If the training is done properly, we get a large language model.

ChatGPT, Copilot, Gemini, etc., are all LLMs, statistical models of text slightly more intelligent than predictive text. That’s why they excel at correcting grammar or rewording texts. That’s also why they are good at programming; after all, programming languages are also driven by grammar rules over a finite vocabulary.

However, they struggle with anything related to logic and reasoning, like doing math or identifying fake news. Luckily for us, human reasoning is also grounded in experience and emotion, so language alone is not enough.

Image generation with diffusion

Generating images is a bit different.

Diffusion models are an evolution of computer vision models that are trained on images with increasing levels of noise.

To generate an image, we start with a noise pattern. Then the model shifts the pixels around to make the image look a little more like what we asked for. This process is repeated several times until the image has no noise.

Diffusion models excel at composition, making them ideal for brainstorming while creating concept art.

However, they are just “pixel shakers”. Like LLMs, they lack experience and feelings, so the images they create often feel uncanny, lifeless, or all look the same.

Diffusion models struggle with video as well, having a hard time maintaining object permanence, understanding the laws of physics, and keeping consistency over time. The first models tried to hide uncanny movements by producing slow-motion videos. They are better now; its likely the training data is now tagged with temporal meta information like motion vectors. Consistency over time is still an issue; not many tools let you create videos longer than 10 seconds, as things start looking like a Doctor Strange movie.

Gen AI in cybersecurity

By Miguel Hernández, Sr. Threat Research Engineer

LLMs have democratized security.

A few years ago, you needed to be a security expert to understand the severity of a security alert, then investigate a solution on the internet, and then implement it.

Now, a chatbot will guide you. First, it looks at your infrastructure’s context to present you with the resources affected, then gathers mitigation steps and helps you implement them. This means that DevOps engineers can also use security tools effectively, and security engineers have extra time to focus on more complex tasks.

This works both ways; security engineers can also use LLMs to investigate where an alert originates in the application’s source code and create more detailed issues for the development team. We saw an example of this in Investigating security issues with ChatGPT and the GitHub MCP server.

On the other hand, Gen AI in cybersecurity also made it easier for cybercriminals. Our Threat Research Team recently detected an attack with indicators that suggest the threat actor leveraged large language models throughout the operation to automate cloud services discovery, generate malicious code, and make real-time decisions. Read more in AI-assisted cloud intrusion achieves admin access in 8 minutes.

These new threats are more unpredictable, which raises the importance of runtime security as a safety net.

What is the hype (and the controversy) about?

By Álvaro Iradier, Technical Product Manager

AI, including LLMs, has been around for decades. So, why all the hype now?

What has changed the game is the increase in computing power.

A few years ago, models were limited to perform specific tasks. Models can now scale to gigabytes of memory, allowing LLMs to solve a wide variety of problems. We are having another wake-up call, as we did in ‘97 when Deep Blue beat Kasparov, and we are thinking that maybe it is now when science fiction becomes reality.

However, AI still hasn’t solved some essential challenges, and that is raising concerns: There are still critical edge cases where AI cannot yet replace humans, AI computing is resource-intensive, and there are ethical questions about how AI software is developed.

As the industry chases AI hype, we must maintain a sceptical mindset, and also separate transformative use cases from those that don’t reduce cognitive burden.

What’s next?

By Marla Rosner, Content Marketing Manager.

So, what will happen next?

We are at a stage where everyone is testing the limits of this new technology. While some people are proposing game-changing applications for AI, most use cases remain novelties.

As things currently stand, AI has democratized some technologies, like coding and security tools. However, they still need a human with real-world experience to guide them.

When LLMs go unchecked, they just create noise. For curl, an open-source command-line tool, things got so out of hand that they have stopped rewarding bug bounty reports and have tweaked the submission process. Real-world experience is still needed.

And while vibe coding has enabled anyone to create a successful project, it has also created a demand for real software engineers to fix glaring scalability and security issues.

At the same time, AI is still evolving.

We are seeing AI chatbots increasingly behave like agents, in what is called agentic AI. In this paradign, AIs use MCP servers to share context across tools, correlate information, and collaborate with other AIs to perform complex tasks.

LLMs are not getting smarter as quickly anymore, but they are able to manage more information and are capable of taking action. This is leading to a new era of automation, where experienced humans are more important than ever.

Read more in AI is still a workload.

Conclusion

Generative AI is just the new kid on the block, grabbing everyone’s attention. But old-school AI still lives in our spam filters, biometrics, profiling, and computer vision.

While Gen AI has democratized many technologies, humans are still needed.

That’s why we’ll see a more surgical approach to Gen AI in the future. Positioned more like a subtle assistant, rather than a human replacement.

If you liked this article, check the other one in the series: