Last Week In AWS Podcast

You Owe Your Country's GDP to AWS

8 min
Jul 20, 2026about 1 month ago
Listen to Episode
Summary

Corey Quinn reviews AWS's latest service announcements and updates, highlighting a billing scare, new AI-focused features, and critical security vulnerabilities stemming from insecure LLM integrations. The episode critiques AWS's pattern of retrofitting features already available elsewhere and emphasizes the security risks of bolting AI agents onto infrastructure without proper safeguards.

Insights
  • AWS is increasingly selling infrastructure abstractions it previously hid, moving from 'serverless' marketing to explicit VM and server management (Lambda micro VMs, managed instances)
  • Security vulnerabilities are clustering around AI/LLM integrations, with multiple CVEs caused by agents being given credential access and logging sensitive data to accessible logs
  • AWS's 'fixes' often solve problems created by AWS's own design choices (75GB Lambda limit, 30-day S3 transition minimums, IP exhaustion from poor planning) rather than genuine customer needs
  • Multi-cloud support announcements (Security Hub for Azure) may signal AWS acknowledging customer workload migration rather than genuine platform maturity
  • Intelligent tiering and other 'innovations' are often decade-old patterns borrowed from other AWS services, suggesting slower feature velocity
Trends
AI workload security becoming critical differentiator as LLM integrations introduce new attack surfacesAWS shifting from abstraction-first to infrastructure-explicit positioning (serverless to VMs)Security vulnerabilities increasingly tied to credential mismanagement in agentic AI systemsMulti-cloud monitoring tools emerging as enterprises diversify cloud providersBilling transparency and cost control becoming major customer pain pointsLegacy protocol support (Layer 2 networking, MAC-based auth) still required for enterprise migrationsServerless compute expanding to include explicit VM-level isolation and controlBulk data operations requiring hidden distributed infrastructure (Glue) despite 'no coding' claims
Companies
Amazon Web Services
Primary subject of the episode; all announced features, services, and security issues discussed are AWS products
Microsoft
Security Hub now supports Azure monitoring; mentioned as competitor platform where AWS is extending security tools
Elasticsearch
Mentioned in context of security vulnerability where LLM agents were given credentials and misused them
People
Corey Quinn
Host and primary narrator analyzing AWS announcements and security issues with critical perspective
Quotes
"I checked mine and considered whether I now owed a small nation's GDP to someone"
Corey QuinnOpening segment
"CloudWatch Logs borrowing the concept feels a little bit less like innovation and more like AWS discovering its own back catalog"
Corey QuinnCloudWatch Logs discussion
"SQS is one of the few AWS services that just works and rarely appears in my inbox at three in the morning"
Corey QuinnSQS 20th anniversary
"We've eliminated serverless from serverless and rediscovered the machine that never turns off"
Corey QuinnLambda managed instances discussion
"Five patches, four of them born from wiring agents to credentials and praying, and one plain old command injection"
Corey QuinnCVE security bulletin analysis
Full Transcript
Welcome to Last Week in AWS, I'm Corey Quinn. AWS started the weekend off early by giving a fair number of us heart attacks before our coffee, sending out bill estimates in the multiple trillions of dollar range. I checked mine and considered whether I now owed a small nation's GDP to someone, and then remembered that, all right, I'd do this for a living, and that number itself was obvious nonsense. But before that, it does feel like getting mugged on the subway. So, condolences to folks who got hit by that. Now, what did AWS actually get into? Let's find out. CloudWatch Logs announces intelligent tiering for storage. S3 got intelligent tiering 10 years ago, so CloudWatch Logs borrowing the concept feels a little bit less like innovation and more like AWS discovering its own back catalog. Three tiers, automatic demotion after 30 and 90 days, and the same eye-watering per gigabyte ingest fee that made you want to filter those logs out in the first place. Cognito now supports importing users with password hashes. Migrating to Cognito used to mean forcing every user to reset their password on day one, which is a great way to teach customers that your new login flow is broken while also triggering fears of a data breach. Now you can import the hashes and skip the mass reset apology email. It only took until 2026. But who's counting? Introducing GuardDuty AI protection for AI workloads. Cost harvesting attacks is a lovely euphemism for someone running up your bedrock bill, which honestly, AWS already does for free. Now GuardDuty watches for prompt injection too, at a price revealed only after the 30-day trial ends and your finance team stops smiling. AWS Organizations now applies account departure security controls by default for new orgs created via the console. Secure defaults that stop accounts from wandering off into the forest applied only to organizations born after this announcement. Everyone else existing sprawl remains as escape as ever The controls are intentionally lightweight which is AWS speak for we didn want the support tickets A rare freebie that costs nothing except your ability to leave Lambda announces self-managed code storage. No additional Lambda charges apply, which is kind, given that you're now paying S3 storage plus cross-region transfer fees to solve a limit AWS invented. The 75 gigabyte quota that spawned a thousand support tickets also quadrupled to 300 gigabytes too, so both fixes arrive on the same day. That's a significant expansion to the Packrat DB school of thought. Stuff things into every free nook and cranny you can in an AWS account. S3 removes 30-day minimum for transitions to S3 Standard Infrequent Access and S3 OneZone Infrequent Access. A decade of forcing everyone to babysit their data for 30 arbitrary days before demoting it, and now that albatross necklace vanishes. Great for cold logs and backups, sure. Just remember the 30-day minimum charge still applies, so transitioning at day zero means paying for storage tiers you're barely using. This is progress, technically. SQS turns 20, two decades of reliable messaging at scale. 20 years old, and the simple and simple queue service still means you're going to spend an afternoon learning what a dead letter redrive is. Credit where due. SQS is one of the few AWS services that just works and rarely appears in my inbox at three in the morning. Happy birthday to the quiet one. You're a goddamn champion. Announcing Lambda micro VMs, serverless compute environments with VM level isolation and near instant startup. So Lambda finally admits it was virtual machines all along, then sells you the machines it was hiding under the abstraction. A decade of don't think about servers now available as here's your server per user with a Docker file. The AI sandbox pitch is a sort of a tell here because Vibe coders needed somewhere to fail expensively Eliminating Java cold starts with Lambda managed instances The fix for Lambda cold starts is running Lambda on EC2 instances you pay to keep warm So you know servers We've eliminated serverless from serverless and rediscovered the machine that never turns off. Congratulations to Java, the language that finally built its way back to the mainframe. Introducing open source bulk executor for Amazon DynamoDB. No coding required, says the tool that spins up hundreds of glue machines behind your terminal prompt. The command line utility runs locally while your bill runs distributed. Handy for bulk deletes and cross-account copies, sure, but just remember that glue meters every one of those hidden workers you are not thinking about. Automating CIDR expansion, reducing IP exhaustion downtime. Running out of IP addresses and not being able to expand contiguously is the natural consequence of forgetting how subnets work, And now you can automate your way out of it with five services stitched together. Step functions, Lambda, DynamoDB, CloudWatch, and IPAM. All conspiring to fix a problem that proper planning solved for free had you but thought to do it. Serverless duct tape, but functional. Setting up Layer 2 networking on EC2. The solution to VPC won't do Layer 2 is apparently run a VPN from a Japanese university to trick Nitro into cooperating. Four architectural patterns, nested virtualization on an M8i.4x large, and apparently a tunnel so your legacy MAC address-based authentication protocol from hell can pretend it's 2004. Cloud native, baby. Security Hub adds AI workload protection and multi-cloud support for Azure. Amazon just launched security monitoring for Azure, which is at least one of A, heartwarming multi-cloud maturity, B, a very polite way of following your workloads to the exit. C a tacit admission that Microsoft isn ever going to fix Azure security because by God are those crayons delicious My favorite detail the customer who discovered a compromised account only because finance flagged the bill I not going to give exact numbers of engagements I had that were AWS that turned into a surprise security incident but it greater than one And finally, five CVEs and the agentic AI security reckoning. Because this week's security bulletin drop reads like a field guide to what happens when you bolt LLMs onto everything and hope for the best. starting with an observability tool that overshared by dumping raw prompts and full responses into CloudWatch for anyone with read access because the agent core SDK decided your user's secrets belonged in a log group. Then there's the strands memory tool that mails your API key wherever an LLM feels like sending it, which is what you get for handing a chatbot your Elasticsearch credential and asking it nicely not to gossip, and the HealthLake MCP server that forwards your temporary creds to whoever crafts the right pagination token in case you wanted an SSRF sitting between attackers and your FHIR records. Not to be outdone by the AI crowd, the load balancer controller sorted its rules by route type instead of specificity, letting any tenant hijack the neighbor's gRPC traffic and turning multi-tenancy into the group project that nobody consented to, while the diff tool built to catch breaking changes will run shell commands if you pass the right arguments, patched alongside the timeless advice to only let trusted actors control the input, which is security guidance on par with don't get hacked. Five patches, four of them born from wiring agents to credentials and praying, and one plain old command injection just to remind you that the classics never went anywhere. Rotate everything. And that's what happened last week in AWS. I'm Corey Quinn. Stick around.