惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
博客园 - 叶小钗
博客园 - 聂微东
博客园 - 司徒正美
Hugging Face - Blog
Hugging Face - Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Google DeepMind News
Google DeepMind News
Recent Announcements
Recent Announcements
IT之家
IT之家
J
Java Code Geeks
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
I
InfoQ
爱范儿
爱范儿
Vercel News
Vercel News
Apple Machine Learning Research
Apple Machine Learning Research
阮一峰的网络日志
阮一峰的网络日志
博客园 - Franky
U
Unit 42
酷 壳 – CoolShell
酷 壳 – CoolShell
腾讯CDC
F
Fortinet All Blogs
V
Visual Studio Blog
人人都是产品经理
人人都是产品经理

Sysdig Blog

Masterclass: AI is more than ChatGPT and LLMs CVE-2026-39987 update: How attackers weaponized marimo to deploy a blockchain botnet via HuggingFace 5 steps to securing AI workloads Marimo OSS Python Notebook RCE: From Disclosure to Exploitation in Under 10 Hours Security briefing: March 2026 The Sysdig MCP server is now available in AWS Marketplace Risk isn’t reduced until you take action: How teams resolve issues in the cloud AI infrastructure security: Why it deserves its own category Three pillars for building effective runtime-powered cloud defense, the right way Closing the cloud security gap with runtime security Seeing risk isn’t stopping it: Why visibility alone isn’t enough TeamPCP expands: Supply chain compromise spreads from Trivy to Checkmarx GitHub Actions AI coding agents are running on your machines — Do you know what they're doing? Runtime security for AI coding agents: Protecting AI-assisted development How runtime insights power every cloud security use case CVE-2026-33017: How attackers compromised Langflow AI pipelines in 20 hours Inline Cloud Response: Accelerating AWS threat containment for SOC teams Runtime malware detection for AWS Fargate Detecting CVE-2026-3288 & CVE-2026-24512: Ingress-nginx configuration injection vulnerabilities for Kubernetes Malware detection with Sysdig Security briefing: February 2026 Leveling up Kubernetes Posture: From baselines to risk-aware admission Eliminating runtime blind spots: How CleanStart and Sysdig build continuous trust across the container lifecycle LLMjacking: From Emerging Threat to Black Market Reality Real risks live at runtime: Why CISOs must care about deep telemetry in 2026 Sysdig named a Leader in the Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 How to run rootless containers AI-assisted cloud intrusion achieves admin access in 8 minutes Security briefing: January 2026 Securing GPU-accelerated AI workloads in Oracle Kubernetes Engine
Use in-use vulnerability prioritization to focus on criti...
Matt Kim · 2026-04-14 · via Sysdig Blog

Vulnerability management has always been a challenge, but today’s security teams are feeling the pressure more than ever. With thousands of new CVEs reported every month, the sheer volume makes it difficult to know where to focus. In-use vulnerability prioritization is one of the most effective ways to cut through the noise, focusing only on vulnerabilities that are actively loaded in runtime.

To focus on what really matters, security teams need better ways to prioritize risk. Instead of trying to fix every critical vulnerability, teams can concentrate on the small percentage that needs to be addressed immediately.

The problem: Vulnerability overload in the cloud

Security teams are drowning in vulnerabilities, with more than 250,000 known CVEs. Every scan uncovers additional issues, making it increasingly difficult to distinguish real threats from background noise. Without a more strategic approach to prioritization, managing these vulnerabilities becomes an unsustainable task.

Many companies have turned to shift-left security to simplify vulnerability management by catching issues earlier in development. In cloud environments, where vulnerability scanning happens at every stage — design, code commit, build, and deployment — the same vulnerabilities may be flagged multiple times, which can slow down development. To stay ahead, organizations need a clear view of risk; however, balancing security with fast release cycles is a constant struggle.

Meanwhile, developers are stuck sorting through endless lists of vulnerabilities, trying to figure out what actually needs to be fixed. Security teams know they can’t ask developers to patch everything; however. Without the right context, vulnerability management often ends up slowing down releases while still leaving critical risks unaddressed. This leads to alert fatigue and wasted effort fixing vulnerabilities that may never be exploited.

Why traditional prioritization frameworks fall short

Many organizations start with using severity scores to prioritize vulnerabilities, assuming that fixing all “critical” and “high” severity issues will reduce risk. While this may seem like a logical approach, it doesn’t scale effectively. Even after filtering out medium and low-severity vulnerabilities, teams are still left with more issues than they can realistically address.

The real problem is that not all vulnerabilities are equally dangerous, even when they are all “critical” severity. Severity alone doesn’t determine risk. Some critical vulnerabilities may exist in packages that are never actually used in production, meaning they can’t actually be exploited by attackers.

Meanwhile, a lower-severity vulnerability that is actively exposed at runtime could provide an entry point for attackers. Without proper context regarding these vulnerabilities, relying solely on severity scores can lead teams to draw the wrong conclusions.

Secure your vulnerabilities – effectively

Vulnerabilities in the cloud are different – make sure your strategy is, too.

Learn More

The solution: In-use vulnerability prioritization

A more effective way to focus on real risks is with in-use vulnerability prioritization, identifying vulnerabilities in packages that are actively running in production, as these are the only ones that can be exploited. By leveraging runtime insights to filter out unnecessary noise, this approach eliminates the guesswork from vulnerability prioritization, letting teams focus remediation efforts where they are most effective.

Sysdig’s vulnerability management solution enables users to identify in-use vulnerabilities with a single click. From there, teams can refine their focus even further with additional filters. They can prioritize vulnerabilities with known exploits, ensuring that actively targeted threats move up the list. They can also filter for fixable vulnerabilities, allowing security teams to spend time on issues they can actually remediate.

In-use vulnerability prioritization

Without an effective prioritization framework, security teams can be stuck manually triaging thousands of vulnerabilities.

With the power of in-use prioritization, security teams can dramatically reduce the number of vulnerabilities they need to address. By isolating vulnerabilities that are in packages loaded at runtime, security teams can reduce their scope to a small fraction of their backlog, in some cases by over 95%.

In-use prioritization helps teams reduce noise, in some cases by over 95%.

Instead of handing developers an overwhelming list of vulnerabilities, security teams can provide a targeted, actionable list. This helps them fix the most significant risks without slowing down innovation.

It's time to be smarter about vulnerability prioritization

Trying to fix every vulnerability is a massive drain on time and resources and ultimately unrealistic. Without a smarter way to prioritize, security teams and developers get stuck in an endless cycle of remediation work, burning out as they sift through vulnerabilities that are not huge risks.

In-use vulnerability prioritization helps cut through this noise. By using runtime intelligence to filter out non-exploitable vulnerabilities, security teams can eliminate unnecessary work, ease developer fatigue, and remediate vulnerabilities faster, strengthening security without getting in the way of development.

Ready to see how Sysdig can help you go from visibility to action? 👉 Request a demo to see how Sysdig works.