Sysdig's threat research team watched one operator work a marimo notebook host for nine hours with hand-written scripts, and the eight-second jump to a bastion host at the end ran on tooling already staged on disk.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 60%
- Investor
- Investor 7%
Reality
- Evidence68
- Adoption66
- Hype gap+8
- Incentives72
- Confidence70
The Sysdig Threat Research Team says stolen cloud keys were checked against ten hosted model services and fronted to buyers, with the compromised tenant paying for every prompt at invocation prices.
Reality
- Evidence62
- Adoption30
- Hype gap+22
- Incentives72
- Confidence58
F5 Labs logged more than 800 attacks and about 32,000 raw events against its honeypots in a month, using an April bypass of Vite's server.fs.deny to read .env files, cloud credentials and terraform.tfstate.
Perspective Coverage
3 publishers
- Builder
- Builder 42%
- Operator
- Operator 51%
- Investor
- Investor 7%
Reality
- Evidence62
- Adoption45
- Hype gap+20
- Incentives55
- Confidence66
F5 counted about 32,000 events in August aimed at .env files and cloud credentials on internet-reachable Vite development servers. The fixed builds are 7.3.2 and 8.0.5, and the advice pairs them with binding the server back to localhost.
Publishers:dev.to · f5.com Reality
- Evidence62
- Adoption42
- Hype gap+15
- Incentives58
- Confidence66
CrowdStrike says the crew queried instance metadata for temporary credentials, enumerated every secret in the cloud credential manager, then used Foundry's cast to derive the Ethereum address behind a stolen private key.
Reality
- Evidence40
- Adoption30
- Hype gap+18
- Incentives68
- Confidence45
F5 Labs logged 69,433 probes at 169.254.169.254 in March 2025 using six ordinary parameter names. Whether any of them mattered was settled at instance launch, before any input validation ever ran.
Reality
- Evidence58
- Adoption32
- Hype gap+22
- Incentives42
- Confidence47
AWS patched seven SDKs and called it a defense-in-depth enhancement. Pi says all seven third-party deployments it tested handed over live credentials, which puts the region field on your audit list.
Reality
- Evidence58
- Adoption62
- Hype gap+16
- Incentives74
- Confidence55
CVE-2026-64849 lets anyone who can reach an MLflow tracking server make it fetch EC2 instance metadata and hand back the response. The fix is 3.15.0; the exposure is a default.
Reality
- Evidence34
- Adoption22
- Hype gap+32
- Incentives28
- Confidence38
Wiz says the VS Code extension auto-loaded MCP server configs from the workspace and handed spawned processes the developer's full environment. Fixed in language server 1.65.0.
Reality
- Evidence62
- Adoption30
- Hype gap+15
- Incentives70
- Confidence55