
AWS GWLB TCP Reset, Azure DevOps Live Migrations to GitHub, GitHub Runner Enforcement, Docker Root Risk, Lambda IAM Updates, PostgreSQL Upgrade Traps, SonicWall Zero-Days & Better Incident Reviews
transcript
show notes
This week on Ship It Weekly: AWS Gateway Load Balancer gets TCP Reset, giving applications a faster way to recover when firewalls or other inline appliances fail instead of waiting minutes for TCP retries to time out. Microsoft puts Enterprise Live Migrations into public preview for moving Azure DevOps repositories to GitHub Enterprise Cloud with data residency while developers keep working. GitHub is beginning enforcement against outdated self-hosted Actions runners. And Omarchy fixes a Docker configuration that effectively gave normal desktop processes a path to root.
The bigger theme this week is failure modes hiding inside infrastructure we already trust. A dead network path can look like a slow application. A repository migration involves far more than copying Git history. A self-hosted runner can quietly become unsupported while it continues looking healthy. And giving a developer access to the Docker socket may sound like convenience until you remember that the Docker group is effectively a root-level privilege.
In the lightning round: Lambda gets full IAM resource-based policies, AWS warns that circular PostgreSQL role memberships can stall major RDS and Aurora upgrades, a researcher releases the FalconFlank CrowdStrike privilege-escalation PoC while CrowdStrike investigates, and SonicWall patches two SMA1000 zero-days after confirming active exploitation.
Links
AWS Gateway Load Balancer TCP Reset
https://www.tellerstech.com/go/s-d7e609ab/
Azure DevOps Enterprise Live Migrations Public Preview
https://www.tellerstech.com/go/s-ea05aff9/
GitHub Actions Self-Hosted Runner Minimum Version Enforcement
https://www.tellerstech.com/go/s-6e8540c4/
Omarchy: Any User Process Can Escalate to Root
https://www.tellerstech.com/go/s-d22971c3/
AWS Lambda Full IAM Resource-Based Policies
https://www.tellerstech.com/go/s-ff2a04b5/
Fix Circular Role Dependencies Before Upgrading RDS and Aurora PostgreSQL
https://www.tellerstech.com/go/s-e4578f52/
FalconFlank CrowdStrike Privilege Escalation PoC
https://www.tellerstech.com/go/s-8c21b00b/
SonicWall SMA1000 Zero-Day Advisory
https://www.tellerstech.com/go/s-559ffc8b/
Remote Incident Reviews: Async First, Live Later?
https://www.tellerstech.com/go/s-68ca9f5e/
This Week’s On Call Brief
Ship It Weekly
https://www.tellerstech.com/go/siw/
On Call Brief





