Host Commentary

Show Notes

This week on Ship It Weekly: AWS introduced Elastic Beanstalk Cluster Mode, allowing multiple applications to run on shared EKS infrastructure while AWS handles much of the Kubernetes complexity. CrowdSec published how a software supply-chain compromise led to attackers copying roughly 170 private repositories using a stolen OAuth token. A critical Next.js vulnerability in ImageResponse can lead to remote code execution through attacker-controlled SVG data. And Microsoft disrupted EvilTokens, a cybercrime platform linked to more than 12,000 compromised inboxes across 10,000 organizations.

The bigger theme this week is what happens after trust has been established. Elastic Beanstalk Cluster Mode puts more infrastructure behind a managed abstraction, but shared infrastructure still means understanding isolation and blast radius. CrowdSec shows how an initial compromise can become a credential problem long after the malicious code is gone. Next.js shows how something as ordinary as generating a social preview image can expose a server-side execution path. And EvilTokens shows how attackers can use valid access to move faster once inside an account.

In the lightning round: F5 has a critical BIG-IP APM vulnerability under active exploitation. GitHub Enterprise Cloud can now export an inventory of credentials with enterprise access, including PATs, SSH keys, OAuth tokens, and GitHub App credentials. Zyxel patched a vulnerability affecting GS1900 switches. And Veeam Agent for Microsoft Windows has a privilege-escalation vulnerability that can lead to SYSTEM access.

And the human closer comes back to CrowdSec. Removing the malicious package, patching the server, or reimaging the workstation does not necessarily end the incident. If an attacker already stole an OAuth token, cloud credential, SSH key, session, or registry credential, that access can survive long after the original compromise is gone. Containment means understanding not only how the attacker got in, but what they took with them

Links

AWS Elastic Beanstalk Cluster Mode

https://tsn.io/1xaV7

CrowdSec Supply-Chain Attack Analysis

https://tsn.io/7yq2f

Next.js ImageResponse Security Advisory

https://tsn.io/8JvHp

Microsoft: Disrupting EvilTokens

https://tsn.io/DtbC9

Microsoft: EvilTokens and Device-Code Phishing

https://tsn.io/ZzwtD

F5 BIG-IP APM CVE-2026-94127

https://tsn.io/sFuKW

GitHub Enterprise Credential Inventory

https://tsn.io/7bpMn

Zyxel GS1900 Security Advisory

https://www.tellerstech.com/go/s-b2595852/

Veeam Agent for Microsoft Windows Vulnerability

https://www.tellerstech.com/go/s-166d3119/

This Week’s On Call Brief

https://tsn.io/Nnd8g

Ship It Weekly

https://tsn.io/NqkdP

On Call Brief

https://tsn.io/Gpz2d

Brian Teller
Hosted by
Brian Teller

25 years in production: DevOps, SRE, platform, and cloud. Host of Kube Signals on KubeFM; DevOps Institute & ITIL Ambassador.

More about Brian Teller →