# A subtle flaw, a massive blast radius. Page: https://stenobird.com/podcast/research-saturday-1377435/a-subtle-flaw-a-massive-blast-radius Text version: https://stenobird.com/podcast/research-saturday-1377435/a-subtle-flaw-a-massive-blast-radius.md Podcast: [Research Saturday](https://stenobird.com/podcast/research-saturday-1377435) Published: 2026-03-21T05:00:00+00:00 Episode link: https://thecyberwire.com/podcasts/research-saturday/417/notes Audio file: https://pdst.fm/e/pdrl.fm/6ec23a/traffic.megaphone.fm/CYBW1689945789.mp3?updated=1774025676 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/a-subtle-flaw-a-massive-blast-radius Duration seconds: 1038 ## Resource Yuval Avrahami from Wiz joins to share their work on "CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild." Wiz Research uncovered “CodeBreach,” a critical supply chain vulnerability caused by a subtle misconfiguration in AWS CodeBuild pipelines that allowed attackers to take over key GitHub repositories, including the widely used AWS JavaScript SDK that powers the AWS Console. By exploiting an unanchored regex filter, unauthenticated attackers could trigger privileged builds, steal credentials, and potentially inject malicious code into software used across a majority of cloud environments. AWS has since remediated the issue and introduced stronger safeguards, but the incident highlights a growing trend of attackers targeting CI/CD pipelines where small misconfigurations can lead to massive downstream impact. The research can be found here: CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/a-subtle-flaw-a-massive-blast-radius/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/research-saturday-1377435/a-subtle-flaw-a-massive-blast-radius.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.