You Owe Your Country's GDP to AWS
8 min
•Jul 20, 2026about 1 month agoSummary
Corey Quinn reviews AWS's latest service announcements and updates, highlighting a billing scare, new AI-focused features, and critical security vulnerabilities stemming from insecure LLM integrations. The episode critiques AWS's pattern of retrofitting features already available elsewhere and emphasizes the security risks of bolting AI agents onto infrastructure without proper safeguards.
Insights
- AWS is increasingly selling infrastructure abstractions it previously hid, moving from 'serverless' marketing to explicit VM and server management (Lambda micro VMs, managed instances)
- Security vulnerabilities are clustering around AI/LLM integrations, with multiple CVEs caused by agents being given credential access and logging sensitive data to accessible logs
- AWS's 'fixes' often solve problems created by AWS's own design choices (75GB Lambda limit, 30-day S3 transition minimums, IP exhaustion from poor planning) rather than genuine customer needs
- Multi-cloud support announcements (Security Hub for Azure) may signal AWS acknowledging customer workload migration rather than genuine platform maturity
- Intelligent tiering and other 'innovations' are often decade-old patterns borrowed from other AWS services, suggesting slower feature velocity
Trends
AI workload security becoming critical differentiator as LLM integrations introduce new attack surfacesAWS shifting from abstraction-first to infrastructure-explicit positioning (serverless to VMs)Security vulnerabilities increasingly tied to credential mismanagement in agentic AI systemsMulti-cloud monitoring tools emerging as enterprises diversify cloud providersBilling transparency and cost control becoming major customer pain pointsLegacy protocol support (Layer 2 networking, MAC-based auth) still required for enterprise migrationsServerless compute expanding to include explicit VM-level isolation and controlBulk data operations requiring hidden distributed infrastructure (Glue) despite 'no coding' claims
Topics
CloudWatch Logs Intelligent TieringAmazon Cognito Password Hash ImportGuardDuty AI Protection and Prompt Injection DetectionAWS Organizations Account Departure Security ControlsLambda Self-Managed Code StorageS3 Intelligent Tiering and Transition PoliciesSQS Dead Letter QueuesLambda Micro VMs and Serverless ComputeLambda Cold Starts and Java PerformanceDynamoDB Bulk ExecutorCIDR Expansion AutomationLayer 2 Networking on EC2Security Hub Multi-Cloud SupportLLM Agent Security VulnerabilitiesCVE Analysis and Credential Exposure
Companies
Amazon Web Services
Primary subject of the episode; all announced features, services, and security issues discussed are AWS products
Microsoft
Security Hub now supports Azure monitoring; mentioned as competitor platform where AWS is extending security tools
Elasticsearch
Mentioned in context of security vulnerability where LLM agents were given credentials and misused them
People
Corey Quinn
Host and primary narrator analyzing AWS announcements and security issues with critical perspective
Quotes
"I checked mine and considered whether I now owed a small nation's GDP to someone"
Corey Quinn•Opening segment
"CloudWatch Logs borrowing the concept feels a little bit less like innovation and more like AWS discovering its own back catalog"
Corey Quinn•CloudWatch Logs discussion
"SQS is one of the few AWS services that just works and rarely appears in my inbox at three in the morning"
Corey Quinn•SQS 20th anniversary
"We've eliminated serverless from serverless and rediscovered the machine that never turns off"
Corey Quinn•Lambda managed instances discussion
"Five patches, four of them born from wiring agents to credentials and praying, and one plain old command injection"
Corey Quinn•CVE security bulletin analysis
Full Transcript