Here’s what our cloud hosts had to say about this week’s episode: 372: Welcome to Microsoft Patch-A-Palooza
Justin Brodley
The burden that Mythos and other high-security LLMs are putting on everyday operations and engineering departments is real. Microsoft patched 972 vulnerabilities in September, 112 of them critical, breaking records they had just set in July and August. On Bolt, I’ve started doing a weekly chore just to review the latest Dependabot findings and address the newest vulnerabilities. Zero Day Initiative’s Dustin Childs points out that AI-assisted discovery is driving the volume, but active exploit rates haven’t spiked to match, at least not yet. If we didn’t have AI to respond to AI-discovered issues, there would be a lot more cranky engineers out in the world.
Speaking of cranky engineers, AWS now distributes root user sign-in across three regions: us-east-1, us-east-2, and us-west-2. Great for resiliency, but your root ConsoleLogin events will now show up in whichever region handled the request. If your CloudTrail logging or alerting only covers one region, someone could be logging in as root right now and you’d never know. I think it’s nuts Amazon rolled this out without warning customers. Go check your trails.
GitHub shared their August availability numbers, and as you can imagine, it wasn’t pretty. The nearly full-day outage on August 17th was a major failure after a string of similar issues. Those reliability problems have kicked off a race to be the GitHub of the AI age, with several companies announcing plans to redesign git systems at scale. This will either amount to nothing, or it will be a big change in the way software has been written for most of my career. I’m already seeing blog posts and tweets calling PR reviews a waste now that AI can generate so much more code with far fewer mistakes. Is that a bad sign for the future of software engineering, or a new renaissance that lets us build the next generation of software?
The one fun story this episode is about contrails. I was on vacation when I saw the headline, and my first reaction was, “Wait, were the conspiracy theorists on to something?” Then I read the article. The fact that contrails have an impact on global warming was a surprise to me, and they’re also relatively easy to avoid. It all comes down to air temperature and the conditions the plane is flying through. Google’s trial with Cathay Pacific estimated a 40% reduction in contrail warming impact just from adjusting routes. There’s even a world map showing active contrails. It’s not real-time satellite imagery; it’s clearly generated from GPS position tracking combined with altitude and weather data.
See you all next week.
Matthew Kohn
For once, I might be on the side of security and compliance. We’ve had years to figure out patch management, and there’s no shortage of tools to help. The days of skipping patches or blowing past your SLAs are over. And it’s not just your operating systems. It’s your dependencies and every piece of software running on your servers. Fall behind, and you will get hacked.
Go forth and patch.

Leave a Reply