Security at machine speed: the Cloud Native Security Track at Edgecase 2026

October 5, 2026

Security isn't a separate department anymore. For most platform teams, it's simply part of the job. That was the starting point for the Cloud Native Security Track, which Sysdig hosted on Edgecase's Security stage. One theme kept coming back all afternoon. AI agents now sit on both sides of the fight, and they move faster than any human can.

A day full of security

The Security stage offered several sessions, starting with a live exam: after a video series together, Marcel Claassen from Sysdig tested Gerrit Tamboer from TrueFullstaq on threat recognition, attack chains, and defense. Alessandro Lo Prete from the Sysdig Threat Research Team then dissected JADEPUFFER, an AI-driven ransomware campaign. A panel with Daniëlle Wagemakers (Sogeti) and Saeid Ashian (Saxo Bank) discussed how platform teams ended up owning security. Marcel returned to close the track with a live demo: an AI attack against a real cluster, and Falco detecting it as it unfolded.

1472 Gerrit Final exam

Gerrit's final exam

Gerrit Tamboer once called himself the LeBron James of vibe coding. Then his colleagues hacked his app in under 20 minutes. After three video sessions with Marcel Claassen from Sysdig, recorded on one of the hottest days of the year in a room without air conditioning, it was time for the live exam. The audience played along in an interactive quiz, complete with Wheel of Fortune jingles and glitter jackets. Behind the fun was a serious message: securing Kubernetes isn't a set of checks you run once before deployment. Security covers the full lifecycle of your workloads. Take Kubernetes Secrets, for example. They aren't encrypted by default, because encoded doesn't mean encrypted. Luckily, most of the audience knew that.


And Gerrit? He passed, finishing ninth in the room. Read the full story of Gerrit's final exam, or catch up on the Gerrit Learns Cloud Native Security video series.

1472 Alessandro Lo Prete Sysdig

Anatomy of an AI ransomware campaign

The Sysdig Threat Research Team tracks attackers that use AI agents to automate their attacks. JADEPUFFER, the name Sysdig gave this attacker, stood out: it was the first one they saw run a full ransomware campaign driven entirely by AI. Alessandro Lo Prete, Threat Detection Engineer at Sysdig, made one thing clear right away: this isn't a Terminator scenario with an AI taking over the internet. JADEPUFFER didn't get in through zero-days, but through known security problems. The difference lies in what happens next.

Where classic attack traffic stays on the surface, an agent keeps going. It looks for credentials, uses them to move to other systems, and all it needs is one misconfigured service to spread through your infrastructure. The work is boring but has a big impact, and now it's fully automated.

There's good news too. So far these attackers aren't very good at staying hidden, and basic security measures stop them. Many organizations just don't have those basics in place. As vulnerabilities get exploited faster and faster, a perfect perimeter is no longer enough, according to Alessandro. Security in depth becomes essential: runtime detection, segmentation, and zero trust. Want to dive deeper? Sysdig wrote about how JADEPUFFER uses agentic ransomware for automated database extortion and about how it later deployed ransomware built to destroy AI models.

1472 platform teams security teams Sysdig

When platform teams became security teams

Next up was a panel discussion about platform teams and security teams. Somewhere along the way, platform teams took on security. They run the admission controllers, patch the base images, and own the pipeline everything ships through. Now they also review code written by AI agents. Daniëlle Wagemakers (Sogeti) and Saeid Ashian (Saxo Bank) discussed how that shift plays out in practice: which open-source tools earned a permanent place, and where platform work ends, and security work begins.

1472 Marcel Claassen Sysdig

The agent that turned

The earlier sessions showed how fast AI agents move on the attacker's side. In the closing talk, Marcel looked at it from the defender's side. He showed how a few hidden instructions in an ordinary README file were enough to turn an AI coding agent against its own environment. Nobody broke in, as Marcel put it. Somebody left a memo, and the agent did the rest, from stealing credentials to covering its tracks.

Preventing an agent from reading those instructions is nearly impossible. What matters is whether you notice when an agent turns against you, and whether you can prove afterward what happened. Marcel showed how Falco rules pick up the attack as it unfolds. The whole attack took less than a minute, so a human who waits for an alert is always too late. An attack at machine speed needs a defense at machine speed.

The attacker never sleeps

The afternoon's message was clear: AI agents make attacks faster, not smarter. The doors they walk through are the same ones platform teams have always had to close. What's changed is how much time you get to notice. Want to know how your platform holds up against an attacker who never sleeps? We're happy to take a look with you.