DevOps Bulletin
Subscribe
Sign in
Home
Chat
Books
Sponsorship
Roadmap
About
Latest
Top
Discussions
Digest #225: GitHub Actions abuse powers a cPanel exploit wave, AWS's Claude apps gateway and auto-applied Terraform
Also: an AI SRE agent that triages incidents before you open your laptop, why your pod died of "out of ephemeral storage" on a half-empty disk, and the…
Jul 31
•
Mohamed Labouardy
3
1
Digest #224: AsyncAPI npm packages hijacked in 8 minutes, 222 fake GitHub repos, an Azure tenant lost in an hour and the death of small PRs
Also inside: HashiCorp's HCL-native policy engine for Terraform, a $19-a-month hosting bill cut to zero, and a Kubernetes rewritten from scratch in Rust…
Jul 24
•
Mohamed Labouardy
3
1
Digest #223: AWS bills a user $140B, a kubelet leak in Kubernetes 1.36, Slack's Shipyard EC2 platform and pods vs AI agents
Plus the four horsemen behind thousands of Postgres outages, how Uber solved the identity crisis for AI agents, and catching full table scans in SQLite…
Jul 17
•
Mohamed Labouardy
3
1
Digest #222: AI breaches AWS in 72 hours, GitHub's agent leaks private repos, Argo CD cluster takeover and Lambda MicroVMs replace CI…
Plus why you shouldn't trust Trusted Publishing, running local models for agentic coding, and PR preview environments that cut staging costs 78%.
Jul 10
•
Mohamed Labouardy
3
3
Digest #221: LLMjacking goes offensive, scaling to 1 million Lambda functions, databases off Kubernetes and Ingress NGINX to Gateway API
Plus: attackers weaponizing stolen AI compute, pgvector at scale on Aurora, Claude Code for IaC, and how to corrupt a SQLite file on purpose.
Jul 3
•
Mohamed Labouardy
4
2
June 2026
Digest #220: Red Hat's npm supply chain attack, malware in AI instruction files, AWS Lambda MicroVMs and a 2x faster test suite
This week in DevOps: the Red Hat npm credential-stealing attack, malware in AI agent files, AWS Lambda MicroVMs, Postgres 19 beta, and how to get good…
Jun 26
•
Mohamed Labouardy
3
1
Digest #219: Fable 5's 1,810-line PR in 30 minutes, GitHub's rebuild revolt, Postgres' only scalable delete and AI-narrated crypto malware
From an AI model opening an 1,810-line pull request on its own in half an hour, to Cursor, GitLab and Zed all agreeing GitHub is broken while…
Jun 19
•
Mohamed Labouardy
4
2
Digest #218: a $500K Google AI hack, Meta AI handing over Instagram accounts, AWS's new FinOps Agent and CockroachDB's vector indexing
Researcher pointed Claude at 3,600 leaked Google API keys and walked away with $500,000 in bounties this week, while attackers got into high-profile…
Jun 12
•
Mohamed Labouardy
4
1
2
Digest #217: Kubernetes ditches Dashboard for Headlamp, Google API keys that won't die, 1-click GitHub token theft and the "Leaving AWS…
Kubernetes Dashboard to Headlamp migration, Google Cloud API key security, GitHub token theft via VSCode, AWS cost optimization, Pulumi EKS, Rust, and…
Jun 5
•
Mohamed Labouardy
3
2
May 2026
Digest #216: GitHub Actions false suspensions, AI agent chains CVE to internal DB in 4 pivots, Gemini 3.5 deletes 28K lines and Postgres for…
LLM agent chains CVE to internal DB in 4 pivots, Gemini deletes 28K prod lines, plus Terraform, Snowflake cost cuts, and K8s scheduling.
May 29
•
Mohamed Labouardy
3
1
Digest #215: AI DevOps Engineer, GitHub's 3,800-Repo Breach, Docker's Hidden microVM API, Terraform 1.15 and compromising Claude Code
A malicious VSCode extension compromised 3,800 GitHub repositories, Rivet's team reverse-engineered Docker Sandbox's undocumented microVM API, Terraform…
May 22
•
Mohamed Labouardy
3
1
Digest #214: GitHub Under AI Load, microVMs Aren't Optional Anymore, AI Assistants Leak Your Chats and StackOverflow Drops Ingress-NGINX
GitHub buckles under AI-generated code volume, pushing users toward Forgejo. Plus: microVM isolation goes mandatory, trackers leak Claude and ChatGPT…
May 15
•
Mohamed Labouardy
4
1
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts