Episode Details

Back to Episodes
365: Linux Drops 432 CVEs, Sysadmins Drop Everything Else

365: Linux Drops 432 CVEs, Sysadmins Drop Everything Else

Episode 365 Published 1 week ago
Description

Welcome to episode 364 of The Cloud Pod, where the forecast is always cloudy! Ryan is out trying to find Hotel California, but Justin, Matt, and Jonathan are in the studio today, and they’ve got a lot of news and some great convo – from privacy in the digital age to Nova models (and a lot of employees) getting the ax, there’s a ton of stuff to cover this week, so let’s get started! 

Titles we almost went with this week

  • Windows Tattletale ID Has No Off Switch
  • Amazon’s Nova Models Enter Witness Protection Program
  • Your PC Has a Secret Name, and Windows Won’t Erase It
  • CloudWatch Watches Your ALB Like a Hawk
  • One Log Group to Trace Them All
  • Duress Code Wipes Phone, Activist Wipes Out Legally
  • Project Perception Sees Vulnerabilities Before You Even Blink
  • Azure DDoS Protection Trades Autopilot for Manual Control
  • Kernel Panic Optional, CVE Overload Mandatory
  • OpenAI’s Keypad: Key Confusion for 230 Dollars
  • China DIYs Its Way Around DUV Export Bans
  • OpenAI Hugged some serious Face
  • Google must pay the EU $1 Billion… that’s a lot of Crepes
  • Amazon apparently doesn’t believe in their AGI

A big thanks to this week’s sponsors:

We’re sponsorless! Want to get your brand, company, or service in front of a very enthusiastic group of cloud news seekers? You’ve come to the right place! Send us an email or hit us up on our Slack channel for more info.

Follow Up 

01:10 Linux kernel team publishes 432 CVEs in two days

  • Update: Linux Kernel CVE Volume
  • The Linux kernel team published 432 CVEs in a two-day span, continuing the high-volume vulnerability disclosure approach the kernel security team adopted after taking over CVE assignment duties directly.
  • This follows the kernel team’s earlier decision to assign CVEs to a broad range of bug fixes, including minor or low-severity code changes, rather than reserving CVEs strictly for exploitable security flaws.
  • The practice remains controversial among sysadmins and security teams, since large batches of CVEs can overwhelm vulnerability scanners, patch management systems, and compliance reporting workflows.
  • For cloud operators running custom or long-term-support kernels, this reinforces the need for tooling that can filter and triage kernel CVEs by actual risk rather than treating every entry as an urgent patch target.
  • The recurring pattern suggests this is now standard operating procedure for the kernel team rather than a one-time anomaly, so listeners managing fleets of Linux-based cloud infrastructure should expect similar large CVE batches going forward.

01:46 Justin – “Everyone is doing a lot of patching these days.” 

04:42 I tried out OpenAI’s new AI keypad — which will be fun for some coders and slightly mystifying to everyone else 

  • OpenAI’s Micro keypad, developed with Work Louder, is now available for hands-on testing, following through on hardware ambitions that were previously overshadowed by legal disputes, including Apple’s trade secret lawsu
Listen Now

Love PodBriefly?

If you like Podbriefly.com, please consider donating to support the ongoing development.

Support Us