Digest #225: GitHub Actions abuse powers a cPanel exploit wave, AWS's Claude apps gateway and auto-applied Terraform
Also: an AI SRE agent that triages incidents before you open your laptop, why your pod died of "out of ephemeral storage" on a half-empty disk, and the one Redis key no amount of sharding can save.
Attackers turned compromised PHP repositories into a botnet this week, using GitHub Actions runners to scan and exploit cPanel and WHM servers at scale.
It is the clearest sign yet that your CI minutes are somebody else's free infrastructure.
Elsewhere, PlanetScale explains how 768 database servers manage to look like one, and AWS shipped a control plane that finally gives platform teams a policy and cost story for Claude Code.
Learn Rogo’s IaC approach
How do platform engineers keep pace with a growing development team at a $2B AI company? On August 11, Lawrence Aiello, Platform Engineering Lead at Rogo, shares how. He’ll cover the modern IaC platforms Rogo weighed, the criteria that mattered, and how infrastructure that runs without attention frees his team to focus on enabling developers. Take Rogo’s criteria into your own platform decision - Register Now
If you have feedback to share or are interested in sponsoring this newsletter, feel free to reach out via LinkedIn or simply reply to this email.
Newsworthy stories
Large-scale GitHub Actions abuse powers a distributed cPanel and WHM exploitation campaign
Why do Kubernetes experts choose managed Kubernetes-as-a-service?
Tutorials of the week
Automate CI/CD troubleshooting with AWS DevOps Agent and GitHub
A green Kubernetes deployment does not mean a healthy application
I built an AI SRE agent that diagnoses incidents before I open my laptop
Videos of the week
Projects of the week
tfplantui turns a Terraform plan into a navigable dependency graph in your terminal.
Widen is a native Postgres GUI for macOS that answers questions in plain English and shows you the SQL before it runs.
tuicr reviews code in a vim-keybound TUI and exports the result straight to GitHub or GitLab.
zeedumper dumps the flagz, statusz and configz pages from Kubernetes components through the API server proxy.
iron-proxy blocks all egress from untrusted workloads by default and swaps sandbox tokens for real credentials at the boundary.






