Bojan Magusic | Dynatrace news https://www.dynatrace.com/news/blog/author/bojan-magusic/ The tech industry is moving fast and our customers are as well. Stay up-to-date with the latest trends, best practices, thought leadership, and our solution's biweekly feature releases. Thu, 21 May 2026 17:09:36 +0000 en hourly 1 How Anthropic Claude Mythos is reshaping the vulnerability landscape https://www.dynatrace.com/news/blog/how-anthropic-claude-mythos-is-reshaping-the-vulnerability-landscape/ https://www.dynatrace.com/news/blog/how-anthropic-claude-mythos-is-reshaping-the-vulnerability-landscape/#respond Wed, 06 May 2026 17:39:46 +0000 https://www.dynatrace.com/news/?p=73923 How Anthropic Claude Mythos Is Reshaping the Vulnerability Landscape

In April 2026, Anthropic unveiled Claude Mythos Preview, marking a major inflection point in how software vulnerabilities are discovered and exploited. The announcement signals a shift in the speed, scale, and sophistication of vulnerability discovery that security teams can no longer treat as incremental. It raises a new, urgent question: how to identify real production risk fast enough to respond.

The post How Anthropic Claude Mythos is reshaping the vulnerability landscape appeared first on Dynatrace news.

]]>
How Anthropic Claude Mythos Is Reshaping the Vulnerability Landscape

What is Claude Mythos, and why does it matter for security?

Claude Mythos is a frontier AI model designed to autonomously discover and chain zero-day vulnerabilities across major operating systems and browsers. Mythos threatens to collapse the window between vulnerability discovery and weaponization from weeks to hours — a shift widely expected to be permanent. Advances in AI have lowered the skill barrier for autonomously discovering and exploiting software vulnerabilities at a scale and speed beyond human capability. This means that the volume and sophistication of CVEs entering the ecosystem are set to increase sharply.

Even though Claude Mythos Preview is not yet accessible to the general public, it has already found thousands of zero-days across every major OS and browser. As AI-driven discovery increases the volume of CVEs, organizations that rely solely on static scanning or pipeline tools will be overwhelmed by findings they cannot meaningfully prioritize. Organizations must prepare for a new reality once Mythos, or tools like it, are more widely available.

For SRE, DevOps, security teams, and AI builders, the question is no longer if your environment contains vulnerabilities — it’s whether you can tell which ones are actually exploitable before an adversary does.

Why traditional vulnerability scanners can’t keep up with AI-driven threats

Traditional security tools — code scanners, static analysis, pipeline checks — can’t see what’s running in production. They generate thousands of results that accurately identify vulnerabilities but fail to evaluate which are exploitable or represent the most risk, leading to alert fatigue and slow risk mitigation, while potentially leaving the biggest risks exposed or undetected.

But there’s a deeper problem: vulnerability exposure is not static. Servers are reconfigured. New application code is pushed to production multiple times a day. Containers spin up and down. Dependencies change with every deployment. A vulnerability that was unexploitable this morning may become reachable by afternoon — and vice versa. Point-in-time scanning tools produce a snapshot that begins aging the moment it’s generated. In a world where Mythos-class models accelerate CVE discovery by orders of magnitude, tools that generate thousands of uncontextualized, static findings are a liability.

A periodic report tells you what was true hours ago. Organizations need continuous, runtime-aware scanning that keeps pace with your environment as it evolves.

Why do AI‑driven threats make runtime vulnerability detection essential?

This is where the runtime security approach fundamentally changes the equation. Rather than cataloging everything that could be risky, runtime security anchors every vulnerability finding in live production context: What is running, what is reachable, and what has real business impact.

Here’s how Dynatrace implements runtime vulnerability detection with built-in risk assessments for the Mythos era:

  1. Filter vulnerabilities to only running components. Dynatrace OneAgent, embedded directly in the runtime environment, continuously monitors which libraries and components are actively loaded and executing. If a dependency exists in your repository but is never invoked in production, it’s automatically deprioritized. Only vulnerabilities in running code are surfaced, which is why customers report seeing significantly fewer vulnerabilities compared to earlier-in-pipeline scanning tools.
  2. Deprecate unreachable (non-exploitable) vulnerabilities. A running library isn’t necessarily an exploitable one. Dynatrace performs deep code-level reachability analysis, tracing actual execution paths and real traffic patterns to determine whether the specific vulnerable function can be reached. If no active call chain invokes it, the finding is deprioritized, enabling teams to focus on vulnerabilities that represent higher risk of exploitation.
  3. Prioritize based on real-time business impact. For confirmed, reachable vulnerabilities, the question becomes: what’s at stake? This is where  Dynatrace’s real-time topology and dependency graph — Smartscape® — becomes essential. Smartscape automatically discovers every process, service, host, and application across your environment and maps how they depend on one another. Think of it as a living dependency graph of your production landscape, continuously updated with every deployment and infrastructure change, making sure the impact-radius analysis is current and not based on a stale inventory.

Smartscape instantly maps which business services are affected, which are internet-exposed, and which connect to revenue-critical workflows, enabling teams to triage on actual business criticality rather than raw CVSS scores alone.

As Mythos-era CVE volumes surge, your teams will receive a focused, continuously updated list of exploitable, business-critical risks.

The Dynatrace platform advantage for AI-driven security

In addition to Smartscape, Dynatrace is underpinned by additional core technical differentiators that make it uniquely positioned for the Mythos era:

  • Grail — A unified data lakehouse that stores and correlates all observability and security data at scale without index limitations, giving RVA the foundation to analyze runtime context across the entire environment.
  • Dynatrace Intelligence— The AI layer powering automated causal analysis, workflow execution, and remediation routing. As CVE volumes scale, human-speed triage becomes unsustainable, making automated, context-aware prioritization and remediation routing — enabled through third-party integrations — the only viable path forward.
  • Dynatrace Vulnerability Feed— A patented, proprietary vulnerability feed that goes beyond standard public CVE databases. The feed rapidly ingests vulnerabilities disclosed through channels such as GitHub Security Advisories and OSV.dev — assessing them against your production runtime. Coverage specifically includes AI frameworks and open-source components relevant to agentic workloads: the fastest-growing attack surface.

Why open source vulnerabilities will surge in the Mythos era

This last point is particularly relevant in the Mythos era. Open source software is where AI-powered discovery tools will generate findings fastest — open source codebases are fully scannable with no license barriers, and GitHub Security Advisories and OSV.dev are precisely where the Dynatrace feed is deepest. When a Mythos-era OSS vulnerability is disclosed, it flows into the feed within hours and is assessed against your production runtime immediately.

As CVE volumes surge, Dynatrace customers will receive a focused, continuously updated list of exploitable, business-critical risks that reflects what’s true in production right now, not what was true at the last scan.

Why security teams should act now

Up until 2025, AI was largely seen in security circles as a risk factor: a source of new vulnerabilities. People with little to no programming experience were suddenly able to publish AI-generated applications at scale, many of which contained fundamental security flaws.

By late 2025, however, AI models had advanced to the point where they could not only introduce vulnerabilities, but actively discover them. Their ability to identify active, exploitable weaknesses in code has been improving rapidly ever since.

Claude Mythos represents a step-change in this evolution. It goes beyond discovering isolated issues to chain vulnerabilities, identifying multiple low-impact flaws that, on their own, may not pose significant risk, but when combined into a sequence of three, four, or more, can be weaponized into highly sophisticated attacks.

Now, before Mythos is publicly available, is the time to prepare. It is critical for organizations to leverage platforms that find critical vulnerabilities that other tools have missed. In a large volume of noise, teams will need to focus on real production risk exposure; not an endless list of unworkable attacks.

By combining runtime observability with security intelligence, Dynatrace cuts through noise and allows faster, more confident remediation through Dynatrace Intelligence and AI-powered agentic workflows.

The Mythos era doesn’t have to mean more chaos. It can be the catalyst for better prioritization through meaningful signals, pressures for faster action, and stronger security posture.

Explore the Playground to see what your next vulnerability report can look like and never miss a zero-day.

The post How Anthropic Claude Mythos is reshaping the vulnerability landscape appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/how-anthropic-claude-mythos-is-reshaping-the-vulnerability-landscape/feed/ 0
Introducing the Dynatrace Vulnerability feed: Accurate, transparent, and threat-aware https://www.dynatrace.com/news/blog/introducing-the-dynatrace-vulnerability-feed-accurate-transparent-and-threat-aware/ https://www.dynatrace.com/news/blog/introducing-the-dynatrace-vulnerability-feed-accurate-transparent-and-threat-aware/#respond Mon, 02 Feb 2026 18:20:34 +0000 https://www.dynatrace.com/news/?p=72958 Dynatrace Vulnerabilities app

Trusted vulnerability data empowers teams to make faster and clearer security decisions. That’s why we’re elevating the Dynatrace Vulnerabilities app with the Dynatrace Vulnerability feed: a new, native source of vulnerability intelligence that’s more accurate, transparent, and threat-aware, helping maintain strong coverage of critical risks. With curated inputs, stronger sourcing, and deeper integration across the […]

The post Introducing the Dynatrace Vulnerability feed: Accurate, transparent, and threat-aware appeared first on Dynatrace news.

]]>
Dynatrace Vulnerabilities app

Trusted vulnerability data empowers teams to make faster and clearer security decisions. That’s why we’re elevating the Dynatrace Vulnerabilities app with the Dynatrace Vulnerability feed: a new, native source of vulnerability intelligence that’s more accurate, transparent, and threat-aware, helping maintain strong coverage of critical risks. With curated inputs, stronger sourcing, and deeper integration across the Dynatrace platform, teams can prioritize what matters most—and act with confidence.

A native vulnerability feed: Agile, precise, and focused on real customer risk

We recognize how quickly noise and alert fatigue can slow vulnerability management. When teams face a high volume of security findings, they require accurate, timely, and reliable threat intelligence to address potential breaches and optimize remediation time, resources, and costs. That’s why Dynatrace is upgrading the Vulnerabilities app to use the Dynatrace vulnerability feed—a new, internally curated source of vulnerability data that replaces the previously used external feed. It delivers more accurate, timely, transparent, and threat-aware vulnerability information, tightly integrated with innovations from Dynatrace security researchers, already recognized through a European patent.

The Dynatrace Vulnerability feed is built on multiple reputable sources, including OSV.dev, GitHub, the National Vulnerability Database (NVD), and vendor advisories, providing comprehensive coverage of vulnerabilities. These insights are further curated and enriched by Dynatrace’s own findings and internal security research.

Key benefits for customers

The new Dynatrace Vulnerability feed is included in the Vulnerabilities app at no additional cost and offers:

  • Trustworthy, high-quality, curated vulnerability data
  • Clearer and more consistent vulnerability descriptions and remediation guidance
  • Strong coverage of critical and high-severity vulnerabilities
  • Improved accuracy for certain findings compared to the previous feed
  • Better long-term agility: Dynatrace owns and evolves the feed based on customer needs
  • Deeper integration with the Dynatrace platform.

Coverage and parity with the previous vulnerability feed

The Dynatrace Vulnerability feed provides full parity with the previously used feed for critical and high-severity vulnerabilities in customer environments. For medium- and low-severity vulnerabilities, we ensure over 90% coverage in customer environments compared to the previous feed, while also adding extra vulnerabilities that were not previously included. Certain medium- and low-criticality vulnerabilities, as well as those without a CVE number that exist solely in the previous feed, will be marked as deprecated (Figure 1).

The vulnerabilities feed within the Vulnerabilities app
Figure 1. The vulnerabilities feed within the Vulnerabilities app

We recognize that coverage is a key topic for organizations when it comes to vulnerabilities. The Dynatrace Vulnerability feed is designed to be dynamic, keeping pace with the large volume of newly reported vulnerabilities. This agility ensures timely updates to meet customer-specific coverage needs, reducing blind spots and protecting against emerging threats. This flexibility is one of the key reasons we decided to introduce our own feed.

What changes for existing vulnerabilities?

From an access and viewing standpoint, nothing changes for existing vulnerabilities. You can continue accessing vulnerability insights from the existing Vulnerabilities app, ensuring a seamless experience with minimal disruption.

Existing vulnerabilities from our previous feed will retain their CVE numbers, but the IDs will be replaced with the Dynatrace Vulnerability IDs (Figure 2). Vulnerabilities from the previous feed without a CVE number will be automatically marked as resolved.

Vulnerability details in the Dynatrace vulnerability feed
Figure 2. Vulnerability details in the Dynatrace Vulnerability feed

If your organization drives vulnerability remediation through an IT Service Management (ITSM) tool like ServiceNow, your existing tickets remain unchanged regarding CVEs and Dynatrace IDs. Tickets linked to vulnerabilities outside the Dynatrace Vulnerability feed will still function, but when accessed, the vulnerabilities might be deprecated, have updated severity, or have an adjusted score.

Availability for SaaS vs. Managed: What You Need to Do

The Dynatrace Vulnerability feed is available in all Dynatrace SaaS environments starting with version 1.334. If you’re on Dynatrace SaaS, this change will happen automatically when version 1.334 is rolled out in March 2026.

If you’re on Dynatrace Managed, an update to version 1.334 (or later) is required to use the Dynatrace Vulnerability feed. Be sure to update to version 1.334 or later before April 1, 2027; otherwise, you’ll no longer be able to analyze vulnerabilities.

Not a Dynatrace customer yet? Try the Dynatrace Vulnerabilities experience in our Playground and see how threat-aware, curated vulnerability intelligence helps you cut through noise and focus on real risk.

Explore the product hands-on in a live environment, and discover how Dynatrace can accelerate vulnerability prioritization and remediation across your stack—start on the Playground today.

The post Introducing the Dynatrace Vulnerability feed: Accurate, transparent, and threat-aware appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/introducing-the-dynatrace-vulnerability-feed-accurate-transparent-and-threat-aware/feed/ 0
Strengthen production security: Bridge SDLC best practices with runtime validation https://www.dynatrace.com/news/blog/strengthen-production-security-bridge-sdlc-best-practices-with-runtime-validation/ https://www.dynatrace.com/news/blog/strengthen-production-security-bridge-sdlc-best-practices-with-runtime-validation/#respond Fri, 09 Jan 2026 16:16:45 +0000 https://www.dynatrace.com/news/?p=72390 Dynatrace bridges SDLC best practices with runtime validation

Modern software systems face constant security threats. While integrating security measures throughout the software development lifecycle (SDLC) helps reduce risks, some vulnerabilities may still go undetected. Combining SDLC best practices with runtime validation helps organizations detect and remediate risks in production environments, ensuring robust, actionable protection while reducing noise and saving teams time by focusing only on the issues that matter most.

The post Strengthen production security: Bridge SDLC best practices with runtime validation appeared first on Dynatrace news.

]]>
Dynatrace bridges SDLC best practices with runtime validation

Recognize the unavoidable need for runtime security

No security strategy can guarantee absolute protection. Modern software complexity and dynamic threats mean some risks will evade detection (Figure 1). According to Dynatrace analysis, a significant portion of Fortune 500 companies remain vulnerable to known vulnerabilities, such as Spring4Shell.

Funnel of security issues and risks from development to production
Figure 1. Funnel of security issues and risks from development to production.

Left-shifted tools often lack runtime context, making it hard to prioritize vulnerabilities by real-world impact. Runtime security bridges this gap by continuously monitoring production environments, detecting and mitigating threats in real time. This approach helps organizations adapt to emerging risks instead of relying on pre-deployment checks.

Dynatrace addresses this challenge by adding runtime context to left-shifted security findings, enabling environment-aware vulnerability prioritization. Dynatrace Application Security integrates seamlessly with third-party tools to ingest and enrich vulnerability data with runtime context. This context-rich prioritization reduces cognitive overload for teams across the SDLC.

The value of defense-in-depth in SDLC

A defense-in-depth approach layers multiple security controls across the SDLC to build resilient applications that can withstand sophisticated attacks. Rather than relying on a single security measure, defense-in-depth supports the strategy that if one layer misses a vulnerability, another will catch it.

This approach gains added relevance as modern development practices accelerate release cycles, often introducing new risks at every stage. By embedding security from the earliest phases of development through to production monitoring, teams can proactively identify, mitigate, and respond to threats before they escalate. Figure 2 illustrates this multi-layered approach, mapping out key capabilities across four critical SDLC phases: Development, Build, Deploy, and Observe (encompassing the commonly referred-to phases of runtime and monitoring).

High-level abstraction of activities across the software development lifecycle
Figure 2. High-level abstraction of activities across the software development lifecycle.

Each phase contributes unique controls and processes to a strong overall security posture. This layered approach is essential for protecting sensitive data, maintaining customer trust and meeting regulatory requirements in an increasingly hostile cyber environment.

To understand how this works in practice, let’s look at an example of a cloud-native microservices application.

End-to-end scenario: How the Astronomy Shop application leverages runtime context

Consider  Astronomy Shop, an online retailer demo application built on containerized microservices such as frontend, product, cart, checkout, payment, order, and search — all deployed on Kubernetes. Astronomy Shop’s teams implement defense-in-depth across the SDLC phases to secure their application.

By leveraging runtime context, they validate and prioritize risks in production, ensuring that the most critical security issues are addressed first. Below is a walkthrough of how Astronomy Shop uses tools and Dynatrace capabilities throughout the SDLC to enhance security.

Effective security starts at the foundation: during development. This phase sets the tone for the entire security lifecycle.

Development phase: Build security from the ground up

Scenario: Developers commit code for services like product, cart, and checkout. Security scanning runs early, and threat modeling identifies sensitive paths (e.g., checkout and payment). Findings are triaged later using the runtime context to prioritize risks.

Sample tools:

  • SonarQube for code quality and static application security testing (SAST), GitHub Advanced Security for dependency monitoring and software composition analysis (SCA).

The Dynatrace role:

  • Ingests security findings from development tools via OpenPipeline’s security events ingest endpoint.
  • Maps findings to the Semantic Dictionary in Grail™ for unified prioritization, analysis, and automation.
  • Highlights critical and high alerts and deprioritizes non-executed code vulnerabilities while prioritizing medium issues exposed to sensitive data. This helps developers focus on vulnerabilities that pose real risks in production.

After development, the build phase is positioned to catch vulnerabilities before deployment.

Build phase: Strengthening security through automation and testing

Scenario: Astronomy Shop teams build and push container images to AWS ECR. Automated image scanning tools like AWS Inspector and Snyk Container assess vulnerabilities. Findings are enriched with runtime context to identify which issues truly impact production.

Sample tools:

  • AWS Inspector for image scanning and Snyk for container scanning.
  • Recommended approach: Artifact/container image scanning for OS and package vulnerabilities.

The Dynatrace role:

  • Extends observability to the build phase for governance and security hygiene control.
  • Adds runtime context to container scans, so developers know which vulnerabilities to prioritize. This simplifies decision making and reduces cognitive load.
  • Automates security gates and workflows with tools like Site Reliability Guardian to ensure no critical vulnerabilities affect production.

And now, we move on to deployment, the critical moment when applications face real-world threats.

Deploy phase: Safeguard production with real-time oversight

Scenario: The Astronomy Shop team deploys services to Kubernetes using Helm or GitOps. Admission policies and baseline checks run, while cloud controls enforce guardrails and flag misconfigurations.

Sample tools:

  • Kyverno for workload and cluster policies, AWS Security Hub for cloud security posture management (CSPM).

The Dynatrace role:

  • Monitors deployment success and audits deployment operations by ingesting SDLC events.
  • Enriches KSPM and cloud misconfiguration findings with runtime context to prioritize critical issues.
  • Detects and addresses configuration issues with Dynatrace KSPM, ensuring continuous monitoring in Kubernetes and cloud environments.

Once deployed, applications should be actively monitored to detect and address emerging threats and potential signs of compromise.

Observe phase: Monitor production for threats

Scenario: The Astronomy Shop application is deployed to production and actively monitored. A new vulnerability is discovered in a library, and Dynatrace detects and locates the issue in real time. Malicious actors attempt to exploit the vulnerability, but the application remains secure due to proactive patching.

Sample tools:

The Dynatrace role:

  • Unifies third-party runtime detections and security signals into a single view for efficient processing.
  • Provides deep runtime observability through OneAgent, extending visibility to process health, cloud, and infrastructure.
  • Enables runtime security capabilities like RVA (Runtime Vulnerability Analytics), Security Posture Management (SPM), and Runtime Application Protection (RAP), serving as the final defense layer against threats.

Figure 3 highlights how Dynatrace integrates seamlessly across the SDLC, enhancing security with runtime context and enabling teams to prioritize and address the vulnerabilities that matter most.

Dynatrace coverage of activities across the software development lifecycle
Figure 3. Dynatrace coverage of activities across the software development lifecycle.

Let’s examine practical scenarios where Dynatrace enhances left-shifted security findings with runtime context, enabling environment-aware prioritization.

Practical scenarios: Elevate security with runtime context

  1. Prioritize SAST findings in code
    Static scanners often detect thousands of vulnerabilities, many of which are irrelevant in production. Runtime context enables teams to prioritize vulnerabilities based on actual risk. For instance, critical severity vulnerabilities in non-executed code could be deprioritized, while medium-severity vulnerabilities exposed to the internet and near sensitive data become high priorities.
  2. Prioritize container scanner findings
    Container scans often flag numerous vulnerabilities. Runtime context helps determine whether these issues truly impact production. For example, a critical vulnerability in a library that is never executed in production can be deprioritized, while containers not deployed in production can be addressed later.
  3. Prioritize KSPM findings on clusters
    Post-deployment, runtime context helps identify which security issues in workload cluster components or configurations impact production services. Critical vulnerabilities with no direct impact on production can be deprioritized, letting teams focus on what matters most.
  4. Prioritize cloud alerts and compliance findings
    Continuous assessment of cloud environments and prioritization of misconfigurations with the application insights reduces the noise from cloud alerts and help to remediate the most important issues first.

Ready to strengthen your security in production?

Explore how Dynatrace can integrate seamlessly into your DevSecOps processes providing application-level insights to security findings across the SDLC for smarter prioritization.

Sign up for a free trial and experience how real-time runtime context makes your organization more secure.

The post Strengthen production security: Bridge SDLC best practices with runtime validation appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/strengthen-production-security-bridge-sdlc-best-practices-with-runtime-validation/feed/ 0
From incident response to everyday analytics: Introducing Dynatrace Investigations https://www.dynatrace.com/news/blog/from-incident-response-to-everyday-analytics-introducing-dynatrace-investigations/ https://www.dynatrace.com/news/blog/from-incident-response-to-everyday-analytics-introducing-dynatrace-investigations/#respond Wed, 07 Jan 2026 18:22:44 +0000 https://www.dynatrace.com/news/?p=72376 Query tree filter

Unlocking actionable insights from data is no longer just a security concern—it’s essential for any team that needs to make sense of large, complex data sets. The recently renamed “Investigations” app (previously known as “Security Investigator”) empowers you to analyze logs, events, metrics, and traces using DQL, transforming raw information into actionable insights that drive business outcomes.

The post From incident response to everyday analytics: Introducing Dynatrace Investigations appeared first on Dynatrace news.

]]>
Query tree filter

Transform how you derive actionable insights from data

Have you ever struggled to make sense of a massive data set or turn raw data into actionable business insights? Investigations handles all this for you—and more—at the scale modern organizations demand.

Whether you’re troubleshooting API call throttling, debugging AWS integration issues, or accelerating root cause analysis, the Investigations app provides a flexible toolkit for exploring your data, allowing you to:

  • Analyze large DQL results in their original form at a detailed level
  • Maintain your entire investigation flow and historical queries in context via the query tree
  • Perform complex investigations on data stored in Dynatrace Grail®
  • Build DQL queries quickly and efficiently based on your findings
  • Save and reuse evidence to refine queries and uncover answers
  • Pivot your queries based on the metainformation attached to log records
  • Analyze the observability metrics connected to your log sources
Figure 1. Derive business insights from data in Grail with Investigations
Figure 1. Derive business insights from data in Grail with Investigations

With Investigations, you can easily navigate through investigation history to review queries and results—streamlining incident response, accelerating root cause analysis, and delivering deeper contextual insights from your data.

Get started with practical use cases

As strong advocates of “learning by doing,” we understand you may be curious about how to start using the Investigations app more broadly. You don’t need to start from scratch—there are plenty of documented scenarios you can customize for your own purposes. To help you get started, explore these informative tutorials:

If threat hunting is more your style, you can start with these tutorial-style investigation challenges:

There are, of course, many more use cases to explore—Investigations can be used with any data in Grail: logs, events, metrics, traces, and even performance data.

Drive insights across all your data

Since its launch, the recently renamed Investigations app has been key to unlocking insights in Grail, allowing teams to analyze metrics alongside logs and connect traces during incident response—this is a game-changer for both security and observability. Over time, the capabilities of the Investigations app were extended well beyond security, supporting a wide range of analytical scenarios.

Despite the name change, all the app’s existing features, including application IDs, which are used in intents and in the browser address bar, remain unchanged, so no updates to integrations or bookmarks are needed. And the roadmap will continue to prioritize incident response and accelerations of investigations.

For ease of use, Investigations will remain listed under “Security” on the Dynatrace platform and in Dynatrace Hub.

For complete details, please see Investigations documentation.

Figure 2. Use cases in the Investigations app
Figure 2. Use cases in the Investigations app

Ready to get started?

Investigations is a built-in app available in all SaaS environments beginning with Dynatrace SaaS version 1.330. Best of all, this app requires no additional subscriptions or privileges—so you can start using it immediately without waiting for access permissions and unlock deeper insights for your business.

The post From incident response to everyday analytics: Introducing Dynatrace Investigations appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/from-incident-response-to-everyday-analytics-introducing-dynatrace-investigations/feed/ 0
Hands-free vulnerability remediation with Dynatrace and GitHub Copilot https://www.dynatrace.com/news/blog/dynatrace-mcp-server-and-github-copilot-coding-agent/ https://www.dynatrace.com/news/blog/dynatrace-mcp-server-and-github-copilot-coding-agent/#respond Tue, 28 Oct 2025 10:32:53 +0000 https://www.dynatrace.com/news/?p=71564 Hand Free remediation - GitHub Universe

In today’s fast-paced development environments, security vulnerabilities can be a major bottleneck, slowing down releases and increasing risks. Traditional approaches to addressing vulnerabilities often involve manual triaging and prioritization, high development efforts, and downtime, which can hinder developer productivity, delay critical fixes, and risk production apps.

The post Hands-free vulnerability remediation with Dynatrace and GitHub Copilot appeared first on Dynatrace news.

]]>
Hand Free remediation - GitHub Universe

The value of automation and agentic AI

The Dynatrace® AI-powered observability and security platform, with its remote Model Context Protocol (MCP) server, revolutionizes this process by integrating observability context into automation and agentic AI-driven workflows. By connecting Dynatrace with GitHub Copilot coding agent, organizations can achieve prioritized and automated vulnerability remediation that not only streamlines security but also maintains system performance and developer efficiency.

Both developers and site reliability engineers (SREs) benefit from this agentic AI collaboration, bringing actionable runtime insights from Dynatrace directly into GitHub and efficiently automating vulnerability remediation.

Automated security remediation with smart runtime verification use case

GitHub Dependabot proactively alerts developers when known vulnerabilities are detected in their projects’ dependencies, helping teams stay secure and compliant. As organizations and projects scale, prioritizing and addressing the alerts becomes a challenge: deciding which vulnerabilities matter most in a given context and streamlining the path to remediation.

Dependabot alerts page
Figure 1. Dependabot alerts page

Let’s dig deeper into two different scenarios, where Dynatrace can help to improve remediation by automating developer tasks and prioritizing work based on impact.

To optimize remediation efforts and minimize release delays, it’s essential to prioritize vulnerabilities based on their actual impact on production applications.

Dynatrace providing context for automating the remediation of GitHub Dependabot alerts

In a typical environment, when streamlining vulnerability remediation, you might utilize GitHub Actions workflows to regularly poll Dependabot. Once a new alert is detected, the workflow creates a new issue and assigns it to the GitHub Copilot coding agent.

To fully understand the problem and its impact, GitHub Copilot coding agent queries Dynatrace—using the remote MCP server—to get additional runtime data. Dynatrace confirms that the vulnerable library is loaded, and that its own Runtime Vulnerability Analytics (RVA) identifies the same issue and verifies the impact by highlighting if the vulnerable function is used in live environments and if it’s exploitable.

Typical high-level architecture for vulnerability remediation workflow.
Figure 2. Typical high-level architecture for vulnerability remediation workflow.

Equipped with the additional context, the coding agent generates a code-level fix. To remediate and prevent insecure code, the fix is added as a pull request to the GitHub repository, awaiting developer review to ensure human oversight.

Once the change is approved and the fix deployed, Dynatrace continuously monitors the environment, verifying the remediation and ensuring the issue is resolved without introducing new problems.

Automate and orchestrate security findings from GitHub Dependabot with Dynatrace Workflows

Unifying and contextualizing vulnerability findings across different tools helps apply prioritization and centralize automation for real-time runtime validation and fix deployment, supporting SREs to minimize potential disruptions to their services.

With the Dynatrace integration for GitHub Advanced Security, you can continuously forward GitHub Dependabot alerts to Dynatrace. Once ingested, Dynatrace uses its capabilities for further analysis, including an RVA verification that provides a contextual understanding of the potential impact on the monitored environment.

Enhanced vulnerability remediation architecture with Dependabot alerts.
Figure 3. Enhanced vulnerability remediation architecture with Dependabot alerts.

The workflow creates a new GitHub issue, including a comprehensive summary of alerts with their confirmation status.

GitHub Copilot Coding Agent automatically picks up the issue and submits the proposed fix for verified alerts as a pull request for a developer to review. This ensures the remediation process remains transparent and allows for human oversight before deployment. Once the pull request is approved and merged, the alert is remediated and the code is secured.

Automated end-to-end security remediation

These two scenarios exemplify how organizations can shift from reactive to proactive security management, automating repetitive tasks and providing actionable insights for developers.

The relationship between Dynatrace and GitHub demonstrates the power of agentic AI in modern software development, where runtime data drives decision-making and empowers coding agents to apply fixes to code environments—all in a standardized way, applying enterprise guardrails.

Reduce your mean time to resolution (MTTR), enhance developer productivity, and ensure robust system security by automating security remediation—all without sacrificing performance or uptime.

The benefits of the coding agent are further amplified with the GitHub announcement of introducing custom agents. Dynatrace has just launched its first custom agent, which seamlessly integrates Dynatrace’s observability and security capabilities into GitHub Copilot, empowering teams to maintain operational excellence, ensure application reliability, and uphold security compliance across the entire software development lifecycle (SDLC).

This allows teams to streamline incident response, perform root cause analysis, validate deployments, triage production errors, and many more use cases—all directly within their GitHub repository workflows.

By delivering real-time insights and actionable data from production environments, Dynatrace extends GitHub’s reach into production, effectively closing the SDLC. Stay tuned for our upcoming blog, where we’ll dive deeper into the powerful capabilities of Dynatrace’s custom agent for GitHub Copilot.

Ready to transform your security workflows?

Explore how Dynatrace can integrate seamlessly into your development landscape using our remote MCP Server and read through our walkthrough documentation.

Sign up for the preview and experience how real-time production context makes your organization more efficient.

The post Hands-free vulnerability remediation with Dynatrace and GitHub Copilot appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/dynatrace-mcp-server-and-github-copilot-coding-agent/feed/ 0