Sysdig is a Cloud & Application Security company founded in 2013 and based in San Francisco, United States. It has raised $744M in total funding, most recently a Series G in 2021 at a $2.5B valuation.
| Date | Stage | Amount | Valuation | Lead investors |
|---|---|---|---|---|
| Dec 21, 2021 | Series G | $350M | $2.5B | Permira, Guggenheim Investments |

Sysdig researchers link the JADEPUFFER AI-agent operator to a second attack deploying ENCFORGE ransomware targeting AI model files.

Sysdig's threat research team documents four ways agentic AI is reshaping the threat landscape in 2026.

Sysdig researchers document JADEPUFFER deploying ransomware designed to destroy trained AI models.

Sysdig researchers document an attacker abusing a single credential across five Azure permission systems.

Sysdig observes threat actors exploiting the Gitea CVE-2026-20896 flaw within 13 days of a patch being released.

Sysdig researchers document the first known ransomware attack run entirely by an AI agent, dubbed JADEPUFFER, which autonomously breached, moved laterally, and encrypted a production database.
Sysdig Secure is the company's CNAPP, unifying cloud security posture management, vulnerability management, permissions and entitlement management, and runtime threat detection and response in one platform. Powered by the open-source Falco engine, it detects threats in containers, Kubernetes, and cloud workloads in real time and uses runtime context to prioritize the vulnerabilities and misconfigurations that are actually in use. Its '555 Benchmark' framing stresses detecting, correlating, and responding to cloud attacks in minutes rather than hours.
Falco is the open-source runtime security engine created by Sysdig and donated to the Cloud Native Computing Foundation, where it became a graduated project with more than 130 million downloads. It taps kernel-level system calls and Kubernetes audit events to detect anomalous and malicious behavior in running containers and hosts in real time, flagging things like shells spawned in containers, unexpected outbound connections, or sensitive file access. As the de facto standard for cloud-native runtime detection, it anchors Sysdig's commercial platform and broader community credibility.
We don't have a live feed for this company's ATS. Their careers page has every open role.
View all careers ↗