# GitHub Supply Chain Attacks, Railway’s GCP Outage, Discord’s Voice Failure, AWS Retry Changes, and Trusted Tool Risk Page: https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/github-supply-chain-attacks-railway-s-gcp-outage-discord-s-voice-failure-aws-retry-changes-and-trusted-tool-risk Text version: https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/github-supply-chain-attacks-railway-s-gcp-outage-discord-s-voice-failure-aws-retry-changes-and-trusted-tool-risk.md Podcast: [Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News](https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275) Published: 2026-05-29T02:00:20+00:00 Episode link: https://rss.com/podcasts/ship-it-weekly/2867837 Audio file: https://content.rss.com/episodes/356364/2867837/ship-it-weekly/2026_05_29_01_44_35_58ab71e8-ca35-4cbb-85de-d132de2397d6.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/episodes/github-supply-chain-attacks-railway-s-gcp-outage-discord-s-voice-failure-aws-retry-changes-and-trusted-tool-risk Duration seconds: 1427 ## Resource This episode of Ship It Weekly is about trusted tools becoming production dependencies. Brian covers a rough GitHub supply chain week, including the compromised Nx Console VS Code extension tied to exposed GitHub internal repositories and the Megalodon campaign abusing GitHub Actions workflows across thousands of public repos. The bigger thread this week is that the tools around production are increasingly part of production. Brian also covers Railway’s GCP account suspension outage, Discord’s voice outage during a Kubernetes migration, AWS changing SDK retry behavior, CVE-2026-9133 in the RabbitMQ AWS plugin, and a Reddit story about stolen AWS keys turning into a $14,000 Bedrock bill. Brian also touches on OpenTelemetry graduating from the CNCF, Claude Code security risk, GitLab Secrets Manager, Google Cloud AI spend caps, and a Redshift Python driver RCE. Full source list and extra links are available on this episode’s page at shipitweekly.fm . Links Nx Console compromise https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised Megalodon GitHub Actions attack https://www.stepsecurity.io/blog/megalodon-mass-github-actions-secret-exfiltration-across-5-500-public-repositories Railway GCP outage https://blog.railway.com/p/incident-report-may-19-2026-gcp-account-outage Discord voice outage https://discord.com/blog/behind-the-scenes-of-the-3-25-26-voice-outage AWS SDK retry changes https://aws.amazon.com/blogs/developer/announcing-updated-retry-behavior-for-aws-sdks-and-tools/ RabbitMQ AWS plugin CVE-2026-9133 https://aws.amazon.com/security/security-bulletins/2026-034-aws/ AWS Bedrock cost spike Reddit thread https://www.reddit.com/r/aws/comments/1tm3ydo/aws_bedrock_cost_spike_14000_usd/ This week’s On Call Brief https://www.tellerstech.com/on-call-brief… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/episodes/github-supply-chain-attacks-railway-s-gcp-outage-discord-s-voice-failure-aws-retry-changes-and-trusted-tool-risk/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/github-supply-chain-attacks-railway-s-gcp-outage-discord-s-voice-failure-aws-retry-changes-and-trusted-tool-risk.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.