A team pointed hundreds of Codex and DeepSeek agents at two PaperCut CVEs and compromised 440+ servers at 395 organizations in 48 countries, going from vulnerability research to the first real victim in under four hours.
The same week, Wiz scanned 3,074 internet-facing LiteLLM gateways and found 294 of them still accepting sk-1234, the master key from the docs, with a path from there to the cloud account's IAM credentials.
Add a .git config that makes Claude Code, Codex and Cursor run attacker code on clone, and this is the week the agents started attacking each other's infrastructure.
If you’re interested in sponsoring this newsletter, feel free to reach out via LinkedIn or simply reply to this email.
Faster GitHub Actions, one line to migrate
Avrea is CI infrastructure for GitHub Actions: you keep your workflows and swap runs-on for one of their labels, and jobs run on high clock-speed CPUs with a colocated cache for dependencies, Docker layers, and build artifacts, plus live observability with SSH into the runner when something is flaky.
I tested Komiser’s workflows on their runners, and the cold run went from 5min to 3min, with the Go test suite at 2min instead of 4min.
Free tier is 3,000 build minutes a month, on Linux, macOS and Windows - Try Avrea for free
My take: what Spotify did to cut Claude Code tokens by 90%, and what you can copy
Newsworthy stories
PaperCut attacker uses hundreds of AI agents to compromise 440+ instances
Nearly 1 in 10 exposed LiteLLM gateways accepted the example sk-1234 admin key
Malicious .git configs can make Claude, Codex, Cursor and other AI agents run attacker code
20x the CI traffic without getting slower: how Datadog rebuilt Git serving
I’ve operated petabyte-scale ClickHouse clusters for 5 years
Tutorials of the week
Implementing chaos engineering in financial payment systems on ECS
Kubernetes disaster recovery: guidance from three reproducible failure scenarios
Distributed tracing for CI pipelines without touching a single workflow file
The Karpenter change that quietly turned on cross-AZ traffic charges
Breaking Claude Code Opus 5 auto mode: RCE from a website summary
Automate IAM Identity Center governance with continuous discovery and reporting
Videos of the week
Projects of the week
walgit hosts git repositories from a single binary in front of an S3 or GCS bucket, with no database, no leader, and no local state that matters.
Mantis gives coding agents security review skills to find, reproduce, and patch vulnerabilities on their own.
Cloud in a Bottle deploys and shares web apps on a server you control, with rootless hardened containers and one login for all of them.
llmfit tells you which open-weight models your CPU, RAM, and GPU can comfortably run, and at what quantization.
argo9s monitors Argo CD applications in real time from a K9s-style terminal UI.
dbmask finds the sensitive columns in a SQL database, masks them with deterministic fakes, and verifies the masking actually happened.
Nightshift wakes your coding agent at night, hands it one small job at a time, and leaves pull requests for the morning.
Meme of the week
Want to reach out to sponsor the newsletter? Book a slot - Q4 dates are open.





