Category Archives: Blog

Why Cloud Breach Dashboards Misstate the Blast Radius

A practical evidence model for separating source volume, confirmed impact, tenant scope and uncertainty in cloud incidents. “Twenty million records exposed” looks like a precise statement. It often is not. The number might describe database rows, user accounts, files, transactions, email addresses or an estimate copied from an early disclosure. It may include duplicates. It […]

Amazon EC2 R9g and R9gd instances powered by AWS Graviton5 processors are now generally available

Today, Amazon EC2 R9g and R9gd instances are generally available, powered by AWS Graviton5 processors. R9g instances are memory-optimized and deliver up to 25% better compute performance compared to Graviton4-based R8g instances, powered by the most energy efficient processor AWS has ever built. R9g instances are ideal for memory-intensive workloads including databases, in-memory caches (Valkey, […]

AWS Weekly Roundup: Welcome DuckLabs to the team, Agentic Resource Discovery (ARD), and more (August 31, 2026)

The news that interested me the most last week was the DuckLabs acquisition. AWS has signed a definitive agreement to acquire DuckLabs, the Amsterdam-based company behind DuckDB, the popular open source analytical database that runs in-process and executes SQL directly against files like Parquet, CSV, and JSON. DuckDB stays open source under its independent foundation […]

AI Can Detect the Threat. Humans Still Have to Decide What It Means

The pitch is simple: models triage faster than people, so the SOC should shrink. That pitch collides with how incidents actually start and how they end. Verizon’s 2025 Data Breach Investigations Report still put a human element in 60% of breaches. Stolen credentials were the most common initial-access path, at 22%. Phishing accounted for 16%. […]

Happy 20th Birthday, Amazon EC2

Twenty years ago today, Jeff Barr wrote a blog post that launched the Amazon EC2 Beta. That single post introduced resizable Linux virtual servers in the cloud, billed by the hour, with one instance type (m1.small) in one Region (US East). It was minimal yet useful, and it changed how the world thinks about computing […]

Zero Trust Was Built for People and Workloads. AI Agents Strain Its Identity Layer.

Many implementations of Zero Trust assume a person is at the other end of the connection. That assumption is now the problem. The core principles still hold. Verify explicitly. Enforce least privilege. Assume breach. None of those are wrong, and none of them go away when autonomous agents enter the environment. What changes is the […]