DevOps Security News

Security in On Call Brief means the parts that land on the platform and SRE teams: the actively-exploited CVE in a dependency you ship, the supply-chain advisory in your CI, the privilege-escalation bug in a managed service you assumed was someone else's problem. We skip the marketing FUD and focus on what's exploitable, what's patched, and what an operator should do this week.

Each brief below distills the week's security-relevant change — patches, advisories, and incident disclosures — with the operator impact called out plainly. It's vulnerability triage for people who own production, not a threat-intel firehose.

All On Call Brief issues

Security in recent briefs

2026-05-31 — 2026-06-06

On Call Brief – Week of May 31–June 6, 2026

The 28-Hour Meltdown: What Happened When AWS US-EAST-1 Overheated; Google Cloud Suspends Railway's Production Account; AWS Organizations emits CloudTrail events for account membership changes - Only…

2026-05-24 — 2026-05-30

On Call Brief – Week of May 24–30, 2026

DevOps'ish 310: The Breaches Are Coming From Inside the Extension Store; The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under…

2026-05-17 — 2026-05-23

On Call Brief – Week of May 17–23, 2026

CISA Credentials, Sensitive Data Exposed in GitHub Repository; GitHub Breach Tied to Malicious VS Code Extension Exposes Thousands of Internal Repositories; Researcher says Microsoft secretly built…

2026-05-10 — 2026-05-16

On Call Brief – Week of May 10–16, 2026

EdTech Firm Instructure Pays Ransom as U.S. House Starts Investigation; Instructure Pays Ransom to Canvas Hackers; Cloudflare: 12 Scheduled Maintenance Windows (Network Performance Issues, Los Angeles,…

2026-05-03 — 2026-05-09

On Call Brief – Week of May 3–9, 2026

How a Cursor AI agent wiped PocketOS’s production database in under 10 seconds; When DNSSEC goes wrong: how we responded to the .de TLD outage; Argo…

2026-04-26 — 2026-05-02

On Call Brief – Week of April 26–May 2, 2026

Microsoft Outlook for iOS still down and out for many after 'service change'; GitHub Faces Scaling Issues as AI Development Surges; China-Backed Groups Are Using Massive…

2026-04-19 — 2026-04-25

On Call Brief – Week of April 19–25, 2026

Everyone Wants Servers And Nobody Wants Servers; ingress-nginx to Envoy Gateway migration on CNCF internal services cluster; Cloudflare: 8 Scheduled Maintenance Windows (Sydney, Salt Lake City,…

2026-04-12

On Call Brief – Week of 2026-04-12

A guide to the breaking changes in GitLab 19.0; 76 The Cost of Assumptions ⚡; Ashby taught us we have to fight fire with fire

2026-04-05

On Call Brief – Week of 2026-04-05

GitHub availability report: March 2026; Another One Bites the Dust: What the CDKTF Deprecation Means for You; Dutch healthcare software vendor goes dark after ransomware attack

2026-03-29

On Call Brief – Week of 2026-03-29

Trivy Supply Chain Attack Hits Docker Images in TeamPCP Campaign; Building SRE Error Budgets for AI/ML Workloads: A Practical Framework; LAX (Los Angeles) on 2026-03-30

2026-03-22

On Call Brief – Week of 2026-03-22

Another One Bites the Dust: What the CDKTF Deprecation Means for You; Windows Server 2025 SMB SID hardening is beachballing legacy clients; DevOps'ish 301: Super Micro…

2026-03-15

On Call Brief – Week of 2026-03-15

Major Breach — McKinsey's Lilli AI system compromised in under two hours, exposing millions of confidential client; Perplexity's Personal Computer system and Mistral's zero-exposure training address…

2026-03-08

On Call Brief – Week of 2026-03-08

Policy in Bedrock AgentCore is now GA; Accelerate Lambda durable functions development with new Kiro power - AWS; 👀 Claude Code now runs while you sleep

2026-03-01

Bedrock throttling, Google Cloud AI updates, and Packer nightlies

[Last Week in AWS] Issue #460: Bedrock Throttling Guide: AWS Publishes Its Own Roast; What Google Cloud announced in AI this month; What’s new with Google…

2026-02-22

Perplexity Computer, Claude Cowork, and AWS security fixes

Perplexity Computer 💻, DeepSeek withholds v4 🐋, Cowork scheduled tasks 💼; Claude Cowork updates 💼, KiloClaw agents ⚡, intelligence yield 🧠; CVE-2025-31133, CVE-2025-52565, CVE-2025-52881 - runc…

2026-02-15

AWS query controls, Cursor plugins, and Helm v4.1.1

[Last Week in AWS] Issue #460: Bedrock Throttling Guide: AWS Publishes Its Own Roast; [Last Week in AWS] Issue #460: Bedrock Throttling Guide: AWS Publishes Its…

2026-02-08

Signal and Hetzner outages, IngressNightmare, and AWS Aurora privilege escalation

Signal Outage [Ongoing]; Hetzner Outage; Privilege Escalation in Aurora PostgreSQL using AWS JDBC Wrapper, AWS Go Wrapper, AWS NodeJS Wrapper, AWS Python Wrapper, AWS PGSQL ODBC…

Scroll to Top