惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Jina AI
Jina AI
云风的 BLOG
云风的 BLOG
人人都是产品经理
人人都是产品经理
T
The Blog of Author Tim Ferriss
阮一峰的网络日志
阮一峰的网络日志
罗磊的独立博客
J
Java Code Geeks
博客园 - 聂微东
B
Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
WordPress大学
WordPress大学
腾讯CDC
L
LangChain Blog
Apple Machine Learning Research
Apple Machine Learning Research
Microsoft Azure Blog
Microsoft Azure Blog
D
DataBreaches.Net
The GitHub Blog
The GitHub Blog
美团技术团队
博客园 - Franky
Google DeepMind News
Google DeepMind News
V
V2EX
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
月光博客
月光博客
The Cloudflare Blog

Sysdig Blog

Masterclass: AI is more than ChatGPT and LLMs CVE-2026-39987 update: How attackers weaponized marimo to deploy a blockchain botnet via HuggingFace Kubernetes 1.36 - New security features 5 steps to securing AI workloads Marimo OSS Python Notebook RCE: From Disclosure to Exploitation in Under 10 Hours Security briefing: March 2026 The Sysdig MCP server is now available in AWS Marketplace Risk isn’t reduced until you take action: How teams resolve issues in the cloud AI infrastructure security: Why it deserves its own category Three pillars for building effective runtime-powered cloud defense, the right way Closing the cloud security gap with runtime security Seeing risk isn’t stopping it: Why visibility alone isn’t enough TeamPCP expands: Supply chain compromise spreads from Trivy to Checkmarx GitHub Actions AI coding agents are running on your machines — Do you know what they're doing? Runtime security for AI coding agents: Protecting AI-assisted development How runtime insights power every cloud security use case CVE-2026-33017: How attackers compromised Langflow AI pipelines in 20 hours Inline Cloud Response: Accelerating AWS threat containment for SOC teams Runtime malware detection for AWS Fargate Detecting CVE-2026-3288 & CVE-2026-24512: Ingress-nginx configuration injection vulnerabilities for Kubernetes Malware detection with Sysdig Security briefing: February 2026 Leveling up Kubernetes Posture: From baselines to risk-aware admission Eliminating runtime blind spots: How CleanStart and Sysdig build continuous trust across the container lifecycle LLMjacking: From Emerging Threat to Black Market Reality Sysdig named a Leader in the Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 How to run rootless containers AI-assisted cloud intrusion achieves admin access in 8 minutes Security briefing: January 2026 Securing GPU-accelerated AI workloads in Oracle Kubernetes Engine
Real risks live at runtime: Why CISOs must care about dee...
Matt Stamper · 2026-02-18 · via Sysdig Blog

Most real risk doesn’t live in theory. It lives at runtime.

As cloud environments become more dynamic, identity-driven, and increasingly shaped by AI, the gap between what security tools see and what security teams can act on continues to widen. Cloud-native application protection platforms (CNAPP) promise consolidation, but many still leave CISOs staring at dashboards full of potential risk, unsure which issues truly matter in the moment.

Now, with the near-universal use of large language models (LLMs) and businesses deploying agentic AI to drive efficiency and lower costs, CISOs face an even more challenging operational landscape replete with new risks that question whether human-in-the-middle timescales will ever be sufficient. 

Securing the AI stack requires runtime-first thinking 

The widespread use of agentic AI across business processes, back-office IT, and security operations (including those from service providers) will tax telemetry and generate additional noise and distraction for security leaders and their teams. Effectively, the ability to ‘detect’ a signal in this noisy environment all but requires that deep runtime telemetry be priority one. 

Too much of the existing security stack is bypassed by a new class of security risk factors that accompany agentic AI and LLMs. As noted in the CISO Desk Reference Guide, CISOs should be asking “What is it that I don’t see, that I should see, and why don’t I see it?” Clearly, we need greater visibility into the cloud and AI stack, including threats to each component organizations rely on. 

Emerging risk factors CISOs must track 

It’s not just that the telemetry may be off, it’s also that the timescales of responses may be woefully too slow – akin to running in wet cement. Sysdig’s 555 Cloud Detection and Response Benchmark (5 seconds to detect, 5 minutes to correlate, and 5 minutes to respond) was a similar wake-up call. The co-pressures of telemetry and real-time/machine-speed response require CISOs to pause and rethink how we view security architecture for a modern enterprise empowered by AI and cloud services. Candidly, security programs face a multitude of new risks that many current tools, absent runtime insights, would miss.

A non-exhaustive list of risk factors that need attention includes the following:

  • Agent entitlements (system, tool, and data access)
  • Agent decision-making (chain of reason, tool instantiation, API calls, etc.)
  • Agent-to-agent communication (profile spoofing, unauthorized data sharing, AITM, rogue agent, etc.)
  • Manifest risks (resource limits, misconfigurations, unidentified dependencies, etc.)
  • Model risks (poisoning, biases, data exfil, RCE, etc.)
  • Protocol risks related to:
    • Model Context Protocol (MCP)
    • Agent-to-Agent Protocol (A2A)
    • Agent Communications Protocol (ACP)
    • Agent Network Protocol (ANP)
  • The provenance of the tools, applications, and protocols to the modern AI stack
  • Business logic risks to agent actions (pricing, inappropriate customer responses, etc.)

At the heart of runtime is visibility on what matters: what's being executed and what's running in production. Runtime is where enterprises generate value. Runtime telemetry can help shed light on the risk factors noted above, be they directly related to AI tools and services or the cloud and microservices that power them.  

Runtime insights are not optional for CISOs 

Runtime telemetry is foundational to the “ity” language that permeates discussions on AI, namely “observability,” “traceability,” and “explainability,” among other similarly synonymous terms. If CISOs were Chief Financial Officers, they’d be focused on key assertions such as completeness, accuracy, validity, and restricted access (CAVR), as well as other financial-statement assertions. The status of these assertions helps validate the accuracy of the organization’s financial statements. Runtime insights into cloud services, AI applications, and AI services are required to provide the parallel assurances needed for AI-enabled applications. 

CISOs face a near-infinite number of risks to their organizations. How they prioritize which risks require attention and mitigation is integral to their roles. Knowing how their organizations derive enterprise value is essential. Enterprises are inherently noisy and ever-changing from a risk management perspective. Focusing on the runtime risks of applications and services that are integral to enterprise value is a pragmatic way to filter and address not only the signal-to-noise challenges but also the increased attack surface and threats enterprises confront. 

When security programs anchor their decisions in runtime truth — what’s running, what’s reachable, and what’s being exploited — the noise reduces, priorities sharpen, and taking action becomes possible.

Runtime insights are no longer optional. They are foundational.