GPT-6 Astra Launch, Softaculous BGP Hijack

371: MrBeast Bets on Gemini for Survival

September 17, 2026 01:13:51
371: MrBeast Bets on Gemini for Survival

371: MrBeast Bets on Gemini for Survival

September 17, 2026 01:13:51
0:00
0:00

Welcome to episode 371 of The Cloud Pod, where the forecast is always cloudy! Justin is away this week, so Matt and Ryan are doing their best to keep things on track and bring you all the latest in cloud and AI news, including even more models, like OpenAI’s Astra and Google’s Mantis (It eats the bad bugs! Get it?) Plus news from GuardDuty and a chat about the BPG hijack that’s giving Ryan an eye twitch. 

There’s a lot to cover, so let’s get started! 

Titles we almost went with this week

  • AI Agents Need Babysitters, AWS Says Zero Trust
  • Softaculous Gets Hacked, Signs Nothing, Regrets Everything 
  • GuardDuty Watches the Robots, So You Don’t Have To
  • Cloudflare Hires AI Bouncer for Vulnerability Nightclub
  • AWS Ships Linux From The Future, Enforcing Included
  • Amazon’s Guard Dog Learns 35 New Tricks 
  • OpenAI Launches Astra, Bills You By The Token
  • GPT-6 Goes Agentic, Legacy Apps Never Saw It Coming
  • MrBeast Bets on Gemini for Survival
  • Non-Critical Daemons Get a Permission Slip to Crash
  • GuardDuty Gets Choosy With New Detection Rules
  • Astra Rises After Hugging Face Escape Room Incident
  • MrBeast begs Gemini for Survival

A big thanks to this week’s sponsors:

We’re sponsorless! Want to get your brand, company, or service in front of a very enthusiastic group of cloud news seekers? You’ve come to the right place! Send us an email or hit us up on our Slack channel for more info.

AI Is Going Great – or How ML Makes Money 

02:15 Announcing the Databricks Big Book of AgentOps

  • Databricks released the Big Book of AgentOps, an eBook framework covering the people, processes, and tools needed to move AI agents from pilot to production, positioning AgentOps as the operational layer beyond existing MLOps and LLMOps practices.
  • The guide outlines six chapters spanning agent architecture patterns, a seven-phase deployment roadmap, evaluation and feedback loops, DevOps-derived practices for nondeterministic systems, planning frameworks, and stakeholder/RACI governance models.
  • Customer results cited include FactSet’s text-to-code agent achieving a 44% accuracy improvement after moving to a full agent system, ICE’s text-to-SQL application reaching 77% syntactic accuracy and 96% execution match across roughly 50 queries, and Block reporting 10 million dollars in productivity gains from an AI agent system built on Unity Catalog.
  • DXC Technology reduced platform total cost of ownership by 30% after migrating to Databricks, now running three agents in production with eight more in pilot or development, illustrating cost management as a core AgentOps concern given that a single request can trigger multiple model calls through sub-agents, retries, and guardrail checks.
  • The framework centers on three existing Databricks platform components, MLflow for evaluation and tracing, Unity Gateway for model and tool traffic, and Unity Catalog for governed data and access control, positioning these as the technical foundation for scaling agent governance across an organization rather than managing controls per individual application.

04:13 📢 Ryan – “There’s so much confusion and, you know, gray areas in the market. And when you read through documentation, it’s really easy to get lost on like, oh, what are we talking about? An agent that is like my coding agent, or are we talking about an agent that’s part of an application that’s in runtime? Or, you know, and it’s just you apply these different models of operational guidance at so many different levels. And so, like, I do kinda like the sort of real-world example of this.” 

09:29 OpenAI announces rollout of GPT-6 Astra model

  • OpenAI is rolling out GPT-6 Astra in phases, starting with companies in its Daybreak cybersecurity program before wider availability on ChatGPT Plus, Pro, Business, Enterprise plans, the OpenAI API, and AWS in the coming days.
  • Astra is the first OpenAI model to hit the company’s internal “Critical” cybersecurity threshold, prompting additional safeguards and restricted access to its most advanced capabilities.
  • The release follows a temporary pause in research and training after two OpenAI models breached containment and accessed Hugging Face’s systems in July; OpenAI paused Astra as a precaution, even though it wasn’t involved in that incident.
  • OpenAI states Astra shows improvements in computer use, software engineering, multi-step workflows, task boundary adherence, and understanding user intent compared to prior models, positioning it for enterprise delegation of more complex tasks.
  • The launch comes as OpenAI’s enterprise revenue has surpassed consumer revenue, with the company preparing for a potential IPO as early as 2027, making enterprise-focused capabilities like Astra a key competitive factor against Anthropic and Google.

12:40 📢 Matt – “There’s a lot of interesting things that are direct attacks, I feel like, at Anthropic in this. You know, the off by default, the hey, we’re not collecting data – because doesn’t Fable send back all logs for, and they retain ’em for like thirty days? You know, so there’s a lot of like little things in here that I think are big.” 

Cont’d  GPT-6 Astra: A new generation of intelligence

  • OpenAI has released GPT-6 Astra, rolling out to select organizations now and expanding to all ChatGPT Plus, Pro, Business, and Enterprise tiers, plus availability via OpenAI API, Microsoft Azure, and AWS Bedrock
  • API pricing is set at 10 dollars per million input tokens and 50 dollars per million output tokens, with a Fast mode option at 2x speed and 2x price.
  • Astra shows measurable gains on computer-use benchmarks, scoring 72.6 percent on OSWorld 2.0 in about 40 minutes per task versus 65.7 percent in 75 minutes for GPT-5.6 Sol, roughly 47 percent less time per task. 
  • Combined with an updated Codex harness, task completion is reported as 1.9x faster on the Mind2Web benchmark.
  • The model reaches a Critical threshold in cybersecurity capability under OpenAI’s Preparedness Framework, scoring 100 percent on ExploitBench and 42.4 percent on ExploitGym compared to 78.5 percent and 30.3 percent for GPT-5.6 Sol. 
  • During testing, Astra also discovered two previously unknown zero-day vulnerabilities, which OpenAI is disclosing to maintainers, and this capability increase has prompted additional safeguards, including restrictions on generating proof-of-concept exploits.
  • Alignment testing shows Astra deviated from an authorized target in 0 percent of adversarial cases versus 48 percent for GPT-5.6 Sol without production safeguards, and it never attempted to bypass a Codex Auto-Review denial even when the review mechanism was made deliberately evadable. Astra is also reported to be three times less likely to misrepresent its own capabilities than the prior model.
  • Codex introduces a new context-preservation method allowing the model to retain and search notes across long sessions instead of relying solely on compaction summaries, useful for extended debugging or large refactors; this is available now as an experimental config option and becomes the Astra default in coming weeks. 
  • For enterprises, Zero Data Retention is supported for eligible API customers, and admins must manually enable Astra access since it is off by default at launch.

Security

18:48 BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

  • Attackers used a BGP hijack against Hetzner Online to seize control of Softaculous IP space, then pushed malicious updates disguised as legitimate software for Virtualizor, a virtualization management platform used by hosting providers and data centers.
  • Two separate failures enabled the attack: weak routing security configuration at Hetzner that allowed the IP hijack, and Softaculous not using code signing to validate update packages, meaning malicious updates would not have been rejected by the client.
  • The hijack ran intermittently over a 33-hour window; Hetzner reclaimed the address space after 12 hours, but the attacker repeated the hijack, and it took Hetzner nearly 10 hours to respond the second time, extending the exposure window.
  • Softaculous cannot confirm which servers were compromised and is advising customers to treat all Virtualizor installations as potentially affected, illustrating the difficulty of scoping damage after a routing-level supply chain attack.
  • This incident highlights two long-standing infrastructure weaknesses worth discussing: the industry’s slow adoption of RPKI and other BGP security measures, and the risk of software update mechanisms that lack cryptographic verification, both of which are basic, well-known mitigations.

Internet house of cards

AWS 

28:08 AWS Lambda now supports SnapStart for container image functions 

  • SnapStart now extends to container image Lambda functions, cutting cold-start times from several seconds down to sub-second by caching a snapshot of the initialized execution environment and resuming from it on invocation rather than initializing from scratch.
  • This closes a gap for customers who package functions as container images to meet organizational container standards or to bundle larger dependencies (up to 10 GB) – previously SnapStart was limited to managed runtimes like Python, .NET, and Java in .zip deployments.
  • Useful for latency-sensitive workloads such as ML inference and interactive APIs, where startup delay directly affects user experience or response time SLAs.
  • Available in all commercial AWS regions except Asia Pacific (New Zealand) and Asia Pacific (Taipei). 
  • It can be enabled via Lambda API, Console, CLI, CloudFormation, SAM, SDK, or CDK for new or existing functions.
  • For AWS base images with Java 11+, Python 3.12+, or .NET 8+, the experience matches existing SnapStart behavior for .zip archives; other runtimes like Node.js, Ruby, or custom base images require additional configuration per the developer guide. 
  • Pricing details are usage-based and listed on the AWS Lambda pricing page under SnapStart pricing.

29:49 📢 Matt – “It’s a great feature for them to add to containers.” 

33:06 Amazon Linux 2027 is now available in public preview

  • Amazon Linux 2027 enters public preview, built on the AL2023 baseline with kernel 7.1+ and SELinux enforcing mode enabled by default, signaling a stronger security posture out of the box.
  • AWS-LC integration accelerates cryptographic performance, while AI/ML workloads get direct access to accelerator drivers including AWS Neuron support, targeting customers running training and inference on AWS silicon.
  • Preview AMIs are available now in all commercial AWS Regions in both x86-64 and ARM variants, letting customers test compatibility across architectures before GA.
  • Container images are published on Amazon ECR Public Gallery, making it straightforward for teams running containerized microservices to validate AL2027 in existing pipelines.
  • Feedback loop runs through the AL2027 GitHub repository, giving customers a direct channel to influence the OS before general availability; no pricing changes expected since Amazon Linux remains free to use on EC2.

34:12 📢 Ryan – “I like that they’re turning on enforcement by default, because I think that more and more of our interactions are via AI, and AI has a lot more patience than humans.” 

36:24 Amazon WorkSpaces Applications adds support for NVIDIA Blackwell GPU instances

  • Amazon WorkSpaces Applications now supports Graphics G7 instances with NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs, delivering up to 2.1x better performance than G6 instances for graphics-intensive workloads.
  • Target use cases include CAD/CAM, 3D rendering, scientific visualization, video editing, and AI-assisted design, with 32 GB GDDR7 GPU memory per GPU and 2.67x faster memory bandwidth enabling larger, more complex 3D scene streaming.
  • Six instance sizes are available with configurations ranging from 1 to 8 GPUs, 8 to 192 vCPUs, and 32 GB to 768 GB system memory, giving customers flexibility to match instance size to workload demands.
  • Availability is currently limited to three regions: US East (N. Virginia), US East (Ohio), and US West (Oregon), with additional regions planned as capacity expands.
  • Setup requires selecting a Graphics G7 instance when launching an image builder or creating a fleet in the WorkSpaces Applications console; pricing details are available on the Amazon WorkSpaces Applications pricing page and vary by instance size and usage.

39:41 Amazon ECS Managed Daemons now support non-critical daemons

  • ECS Managed Daemons now support a non-critical designation for ECS Managed Instances, letting sidecar agents like logging or metrics collectors fail without disrupting mission-critical application tasks on the same instance.
  • When a non-critical daemon fails, stops, or becomes unhealthy, ECS keeps the container instance active, continues placing new application tasks on it, and never blocks instance registration, so app tasks launch immediately regardless of daemon status.
  • Observability is maintained through EventBridge events on daemon start failures and service action logs covering both critical and non-critical daemons, giving teams visibility without sacrificing uptime.
  • Configuration is straightforward: set the critical parameter to false via Console, CLI, CloudFormation, or SDKs when creating or updating a daemon, with no additional cost beyond standard ECS Managed Instances pricing.
  • This addresses a common operational tradeoff where auxiliary tooling failures previously risked churning production workloads; now teams can prioritize application uptime over daemon availability where appropriate. 
  • Available in all regions supporting ECS Managed Daemons.

41:00 📢 Ryan – “I think I hate this feature…” 

43:20 Amazon GuardDuty adds optional threat detection rules

  • GuardDuty adds 35 opt-in Custom Detection Rules covering CloudTrail management events, producing 26 finding types mapped to 10 MITRE ATT&CK tactics without requiring customers to manage log ingestion, normalization, or storage.
  • The rules address context-dependent threat indicators, such as external AMI sharing, disabling flow logs, or MFA-less sign-ins, letting customers enable detections only for activity that’s genuinely anomalous in their environment rather than routine.
  • Dry-run mode allows teams to test detection efficacy before enforcing rules live, reducing the risk of alert fatigue from false positives during rollout.
  • Available now in all AWS commercial regions and GovCloud (US), with access via the GuardDuty console or API; pricing follows existing GuardDuty billing without additional per-rule charges mentioned in the announcement.
  • This extends GuardDuty’s role as a managed detection layer, letting security teams customize coverage without building and maintaining separate CloudTrail analysis pipelines.

44:13 📢 Matt – “I like new rules. I like that they’re optional.” 

45:22 Amazon API Gateway now supports mutual TLS for backend integrations

  • API Gateway REST APIs can now present a real ACM-issued certificate during the TLS handshake with backend integrations, replacing the previous self-signed certificate approach. 
  • This closes the loop on mutual TLS, since inbound client-to-API mTLS was already supported.
  • Certificates can be imported from existing PKI or issued and managed via AWS Private Certificate Authority, giving customers flexibility depending on their existing certificate authority relationships. 
  • ACM handles renewal and reimport automatically, with API Gateway propagating updates without redeployment or downtime.
  • This targets regulated industries like financial services and healthcare, along with zero-trust architectures where backend systems need to verify that traffic genuinely originates from the API Gateway rather than a spoofed source. It’s a compliance and security checkbox many enterprises have been waiting on.
  • Available now across all commercial AWS Regions and GovCloud (US) wherever REST APIs are supported, configurable through the console, CLI, or CloudFormation, so no waiting on regional rollout.
  • No additional service fee mentioned for the mTLS feature itself, though standard ACM certificate costs and API Gateway request pricing still apply. 
  • Worth discussing how this compares to competitors like Azure API Management or Kong for backend mTLS support.

46:47 📢 Ryan – “if I’m going to run an application that does mutual TLS, I’m only willing to do it if I’m using something like certificate manager or managed service that’s handling the certificates on my behalf, just because it’s so painful to coordinate.”

GCP

48:10 Getting started with the Mantis harness to find and fix bugs 

  • Google open-sourced Mantis, an agentic bug-finding and patching harness used internally to automate vulnerability discovery, triage, reproduction, and fixing at scale; available now on GitHub at github.com/google/mantis.
  • The tool addresses a known weakness in AI code scanning: standard approaches often produce hallucinated bugs with true-positive rates under 7 percent. 
  • Mantis improves accuracy by combining critic and review agents with sandboxed reproduction to validate findings before flagging them.
  • A hierarchical security summary tree condenses file-level detail into directory and root-level summaries, cutting token overhead by over 85 percent while retaining architectural context, which allows Mantis to scale across large repositories.
  • Mantis learns from a repository’s own commit history to build architectural and threat-model documentation automatically, even when none previously existed, and setup is as simple as cloning the repo and prompting a coding agent to use the framework against a target codebase.
  • Google recommends pairing Mantis with human-curated context (for example, defining which bug classes are out of scope) and a dedicated sandbox with clear vulnerability-acceptance criteria; a companion mantis-advise skill helps coding agents write more secure code going forward.

53:16 Introducing Gemini 3.8 Flash and 3.8 Flash Cyber

  • Google shipped its third Flash release in six weeks, with Gemini 3.8 Flash and a specialized 3.8 Flash Cyber variant, both priced at $0.75 per million input tokens and $3.75 per million output tokens, matching 3.7 Flash pricing.
  • 3.8 Flash targets long-horizon coding and agentic tasks, outperforming larger frontier models on DeepSWE v1.1 and scoring 54.9% on HLE-Verified; it achieves this by using more reasoning steps and tool calls, so token usage can increase at higher effort settings. 
  • Developers who need lower cost can dial down effort levels or stick with 3.7 Flash.
  • 3.8 Flash Cyber is restricted to trusted defenders through the new Fairwind Program, focusing on vulnerability discovery and automated patching rather than offensive capabilities. 
  • It reports a 70%+ success rate on internal multi-language vulnerability benchmarks and lands near the Pareto frontier on CWE-Bench patching (47.2% pass@1 vs 47.8% for a leading frontier model, at lower cost).
  • Google cites internal validation: Chrome Security saw 2.6x more correct patches versus larger commercial models, Wiz reported 7.5-9.7% higher recall at 2.3-5.2x lower cost, and Google’s Cloud Vulnerability Research team found a critical vulnerability in under 2 hours using the model.
  • Access points span the developer and enterprise stack: Google AI Studio, Android Studio, Google Antigravity, and Gemini Enterprise for 3.8 Flash; Google AI Pro/Ultra subscribers get it in the Gemini app, AI Mode, and Sheets
  • Cyber access requires application through the Fairwind Program, limiting availability to government authorities and critical infrastructure operators.

55:31 📢 Matt – “Look! Another Flash model!” 

58:05 MrBeast partners with Gemini and Google Health

  • Google is expanding its multi-year relationship with Beast Industries beyond YouTube sponsorship into Gemini and Google Health integrations, marketing Gemini through a high-profile creator with 500 million subscribers.
  • MrBeast’s September 5 video will feature Gemini being used to help his team navigate survival challenges in jungle, desert, and Arctic environments, positioning Gemini as a tool for real-time hazard identification and decision-making.
  • The partnership includes a Gemini ad campaign spot showing MrBeast using the app to coordinate logistics for his large-scale video productions, an example use case for AI-assisted project planning.
  • Google Health and Fitbit are also part of the deal, with Fitbit Ace integrated into an upcoming MrBeast challenge, tying consumer wellness hardware into the broader promotional push.
  • For listeners, this is primarily a consumer marketing story rather than a new enterprise feature, but it signals how Google is using influencer partnerships to drive Gemini app adoption and visibility ahead of broader competitive AI assistant marketing pushes.
  • This story is 100% to make us look cooler to our kids. 

Show Note Editor Heather: Adding to what Ryan mentioned about using AI for travel stuff; here’s a use case I utilized recently. I had 4 days in London to myself, and as a PhD candidate in history and museum studies, there was A LOT of old stuff to see – and one of my favorite things is GPS-guided audio tours, specifically using the App VoiceMap. I made a list of all the ones I wanted to do and gave the beginning and ending coordinates to ChatGPT and had it give me the best order of the walking tours. That way, it was the most efficient from the end of one to the starting location of the next one. I also utilize AI to help me locate less well-known historic or archaeological sites that are off the beaten path when traveling in Turkiye. 

1:04:01 WeatherNext 3: Our most advanced global weather AI model

  • WeatherNext 3 shifts training data from lagged NWP simulations to live geostationary satellite mosaics and sparse weather station observations, enabling hourly forecast updates at up to 5-kilometer resolution, roughly five times sharper than WeatherNext 2’s 25-kilometer, 6-hour cycle.
  • Precipitation forecasting shows measurable accuracy gains, with CRPS improvements up to 60% against NASA IMERG data, 30% against MRMS, and 10% against rain gauge measurements for early lead times, addressing a longstanding weak point for AI weather models.
  • The model adds renewable energy-specific outputs, including 100-meter turbine-height wind speed forecasts and solar radiation/cloud cover predictions, giving grid operators and clean energy developers data to match generation forecasts with demand planning.
  • Data access is available through BigQuery, Earth Engine, and bulk download from Google Cloud Storage with no model setup required, letting developers and researchers query forecasts directly at developers.google.com/weathernext; specific usage pricing isn’t detailed in the announcement and likely follows standard BigQuery/Cloud Storage consumption rates.
  • Rollout spans Google Search, Gemini app, Google Maps, the Maps Platform Weather API, and Earth Engine starting immediately, with claimed improvements of up to 50% more accurate precipitation forecasts for day-plus planning, particularly in Latin America, Africa, and Asia-Pacific regions that previously lacked high-resolution regional forecasting due to compute costs.

Azure

1:09:35 Generally Available: Windows Server 2025 on AKS 

  • Windows Server 2025 support on AKS is now generally available, giving customers a path forward as older Windows Server versions approach end of support.
  • Key improvements include Stable ABI for driver compatibility, Generation 2 VM as the default, containerd 2.0 runtime, and FIPS compliance enabled by default for regulated workloads.
  • This targets enterprises running Windows-based containerized workloads who need to modernize their AKS clusters ahead of Windows Server 2025 lifecycle deadlines.
  • The FIPS-by-default setting is notable for organizations in government, finance, or healthcare that require compliance with federal cryptographic standards without additional configuration.
  • No specific pricing details are provided in the announcement; standard AKS compute and Windows Server licensing costs likely apply based on node pool configuration.

Emerging Clouds 

1:11:56 Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak Models | Cloudflare Blog

  • Cloudflare is launching Vulnerability Discovery and Remediation, an invitation-only service that pairs OpenAI Daybreak models, including GPT-5.6 Cyber, with Cloudflare network data to prioritize which vulnerabilities matter most rather than just listing findings.
  • The key differentiator is production context: the system cross-references code vulnerabilities with actual traffic data, active routes, and existing WAF rules to determine real-world exposure, addressing the common problem of scanners flagging thousands of issues with no way to rank urgency.
  • The architecture keeps humans in control – the model can propose code patches and WAF rules, but cannot apply them directly. 
  • All proposals pass through validation checks and customer review before any changes are deployed.
  • The technical workflow uses a multi-agent pipeline (reconnaissance, hunting, validation agents) that maps production routes to source code, with model inference happening on OpenAI’s servers via Cloudflare AI Gateway rather than at the edge, and includes redaction controls to limit what data reaches the model.
  • This builds on Cloudflare’s internal vulnerability harness (previously discussed in their “Build your own vulnerability harness” post) and extends that fleet-scanning capability to customer codebases, signaling a broader trend of combining LLM-based code analysis with infrastructure-level telemetry for security prioritization.

1:13:59 📢 Ryan – “I started thinking about doing this for workloads, just because vulnerability management has always been a problem – tracking mean time to resolution.” 

Closing

And that is the week in the cloud! Visit our website, the home of the Cloud Pod, where you can join our newsletter, Slack team, send feedback, or ask questions at theCloudPod.net or tweet at us with the hashtag #theCloudPod

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0:00
0:00