# GitHub API Enumeration, Grok Build CLI Data Exposure, AWS Security Hub Network Scanning, AI-Powered Patch Pressure, and Why Visibility Is Not Ownership Page: https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/github-api-enumeration-grok-build-cli-data-exposure-aws-security-hub-network-scanning-ai-powered-patch-pressure-and-why-visibility-is-not-ownership Text version: https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/github-api-enumeration-grok-build-cli-data-exposure-aws-security-hub-network-scanning-ai-powered-patch-pressure-and-why-visibility-is-not-ownership.md Podcast: [Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News](https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275) Published: 2026-07-18T01:00:24+00:00 Episode link: https://rss.com/podcasts/ship-it-weekly/3000737 Audio file: https://content.rss.com/episodes/356364/3000737/ship-it-weekly/2026_07_18_00_47_49_894e96b5-5f90-4a97-9c70-e016adbfcb7c.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/episodes/github-api-enumeration-grok-build-cli-data-exposure-aws-security-hub-network-scanning-ai-powered-patch-pressure-and-why-visibility-is-not-ownership Duration seconds: 1156 ## Resource This week on Ship It Weekly : Datadog tracked coordinated GitHub API enumeration, xAI’s Grok Build CLI reportedly uploaded repo data without redaction, AWS Security Hub added Network Scanning and exposure impact analysis, and Microsoft says AI-powered vulnerability discovery is changing patch pressure. The theme: visibility is not ownership. A GitHub API map does not revoke a token. An exposure finding does not close a port. A patch bulletin does not patch the fleet. And an AI coding tool reading your repo is still access. Brian covers GitHub as a production surface, AI coding tool data boundaries, cloud exposure based on reachability and blast radius, and why patching needs to look more like production operations than spreadsheet theater. Also, the Ship It Weekly shop is open at shop.tellerstech.com with Ship It Weekly t-shirt designs. Use coupon code SHIPTHESTORE for 20% off your order for the next few weeks. Links Datadog: Coordinated GitHub API enumeration https://securitylabs.datadoghq.com/articles/coordinated-github-api-enumeration/ The Verge: Grok Build CLI repository upload report https://www.theverge.com/ai-artificial-intelligence/965600/spacexai-grok-build-repository-upload AWS Security Hub Network Scanning https://aws.amazon.com/about-aws/whats-new/2026/07/aws-security-hub-network-scanning/ AWS Security Hub impact analysis for exposure findings https://aws.amazon.com/about-aws/whats-new/2026/07/impact-analysis-aws-security-hub/ Microsoft: Windows vulnerability management and AI-powered discovery https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/ SRE Weekly Issue 525 https://sreweekly.com/sre-weekly-issue-525/ HalluSquatting / hallucinated package risk https://www.endorla… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/episodes/github-api-enumeration-grok-build-cli-data-exposure-aws-security-hub-network-scanning-ai-powered-patch-pressure-and-why-visibility-is-not-ownership/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/github-api-enumeration-grok-build-cli-data-exposure-aws-security-hub-network-scanning-ai-powered-patch-pressure-and-why-visibility-is-not-ownership.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.