The B2B Podcast Index
Ship It Weekly

Cloudflare BYOIP BGP Withdrawals, Clerk’s Postgres Query-Plan Flip Outage, and AWS Kiro Permissions Lessons (Grafana Privesc + runc CVEs)

Ship It Weekly · 2026-02-27 · 18 min

Episode notes

This week on Ship It Weekly , Brian looks at how the boundary of ops keeps expanding. We cover AWS flagging issues in Bahrain/UAE amid Iran strikes, ArgoCD vs Flux and why ArgoCD can get stuck in failed sync states, GitHub Actions being exploited at scale (plus Trivy’s incident), RoguePilot prompt injection meeting real credentials in Codespaces, Block’s “AI remake” layoffs, and Anthropic’s Claude Code Security for defenders. Lightning round: DeepSeek model access geopolitics, Vercel’s agentic security boundaries, a KEV CVE to patch, an MCP-atlassian SSRF-to-RCE chain, and Claude Cowork scheduled tasks. Links AWS Bahrain/UAE (Reuters) ArgoCD to Flux GitHub Actions exploitation Trivy incident RoguePilot Block layoffs (WSJ) Claude Code Security DeepSeek (Reuters) Agentic boundaries CISA KEV mcp-atlassian CVE Claude Cowork tasks More:

More from Ship It Weekly

All episodes →
Explore the best B2B Engineering & DevTools podcasts →
Listen to this episodeAll Ship It Weekly episodes →