1.2K Followers
884 Following
3.6K Posts
#cryptography and cloud infrastructure naga #infosec #appsec
Not into internet fun money
Bloghttps://cendyne.dev/
Preferred / Sys nameYellow
PronounsNo third person pronouns for me please, just say Cendyne / you
Microsoft gets tired of “Microslop,” bans the word on its Discord, then locks the server after backlash

Microsoft blocks the word Microslop on its Copilot Discord, bans users, and locks channels after backlash, showing tensions around its AI push

Windows Latest

Two AWS outages, including the 13 hours one, were caused by coding agents deleting what they shouldn’t, in production.

AWS points to the engineers:
“We’ve already seen at least two production outages,” one senior AWS employee told the publication. “The engineers let the AI resolve an issue without intervention. The outages were small but entirely foreseeable.”

Coding agents are everywhere, they are privileged, we have zero visibility into what they do, and they bypass classic CI/CD and cyber defense controls.
Even finance is using them. I’m unsure how much engineers could actually do to prevent these incidents.

If you are concerned by these, I’d start by asking the following questions:
- What coding agents are you running?
- What MCP servers, extensions, or skills are your developers using?
- Do you have preventative controls for agents stepping out of bounds?
- Do you have detection and response capabilities to stop attacks?

Original article:
https://www.tomshardware.com/tech-industry/artificial-intelligence/multiple-aws-outages-caused-by-ai-coding-bot-blunder-report-claims-amazon-says-both-incidents-were-user-error


And if you made it this far, defending agents is what I do.
If you want to see a demo of how you can discover and protect agents, drop me a line.

Knostic has been doing this for a while, unlike the 50 vendors now rebranding themselves in the space. :)

https://knostic.ai/

@soatok incidentally this happens in my head every time I accidentally read the comments somewhere
@chr the dragons (and more) will be appreciated.
I need to sleep and all I can think while the music plays is my head is: THE CORNELL BOX MUST BE RENDERRD

Why think about valentines when I could think about egg

Or more specifically a WYSIWYG editor for my bespoke document format that I use on my blog

Reading generated job descriptions fills me with dread. And sighs.

Some things are left unsaid like "Hey, you know how to communicate right? Orally and in written form? Gotta cover our bases, in case you do pass our interviews"

AI agent "contributes" PR to matplotlib.
PR gets rejected.
AI agent *writes and publishes blog to shame the maintainer*.

What a time to be alive.

https://github.com/matplotlib/matplotlib/pull/31132

I'm having this weird cognitive dissonance where I'm using the same tactics for a forgetful LLM agent with a person. I have to gradually refine my memos and share them multiple times a week. Each has a very condensed and to the point communication (unlike his GPT gen work) with links to other memos.
Nothing like doing near-midnight database maintenance for a micro service that's no longer being actively used to avoid aws extended support fees