Uploaded August 2026 | Updated September 2026, 1 hour ago
Somebody out there is running an app in production with the heap actuator exposed. We know because a threat intelligence team got into a foreign state hacker's machine, went through the toolkit, and found a tool built specifically to read application memory through it. Nobody writes that tool for a thing nobody does.
@thecote and David Zendzian spend the episode on the unglamorous version of AI security. David walks the recent agent breakout write-up step by step and stops at each point where a platform would have ended it: the container couldn't have written to the filesystem, couldn't have run as root, couldn't have reached the metadata endpoint, and couldn't have gotten anywhere useful once it was out. His framing is a two-word flip he keeps coming back to. Secure by default means here are all the options you could use. Default secure means we already decided, and you have to acknowledge it to change it. Coté pushes on where that opinion actually comes from, gets a policy definition out of him, and then defines a mayonnaise standard in full legalese.
Topics:
- Why "secure by default" and "default secure" are opposites, and which one you actually shipped
- What a compromised container can reach when application security groups mean it can reach three things, and why blast radius is the number that matters
- The nation state toolkit with a Spring heap actuator exploit in it, and what its existence proves about production
- Why nobody should be writing their own Dockerfile, and what golden images cost the people who maintained them
- How credentials used to move (a ticket, a DBA, an email, a config file) and what breaks when nothing in that chain has to exist
- Attacking the AI that's watching you, by writing a log line it will read as a prompt
- What 400 phone calls in a row means when somebody is standing in a bank with your name
Chapters:
00:00 Black Hat, and the security-conscious person's answer
00:47 The agents that named their files ZZ so nobody would scroll down
03:01 "Have you had your own agents talk to each other?"
03:13 An agent per NPC, and advancing a whole village by 24 hours
06:21 How does an agent know the prompt came from you and not another agent
07:53 Walking the breakout backwards: no root, no filesystem, no foothold
11:20 Secure by default means you could have. Default secure means we already did
13:28 What an application security group is, and why blast radius is the real number
14:36 Policy, and what a mayonnaise standard looks like in legalese
15:58 A nation state's toolkit had a Spring heap actuator exploit in it
20:26 Golden images, and why you'd want the build to happen before production
21:58 Reproducible builds, transitive dependencies, and needing an AI to read the AI's code
25:22 The old life of a credential: a ticket, a DBA, an email, a config file
28:08 Knowing who's talking to you, and knowing whether to do what they say
29:18 The metadata endpoint, and credentials that should not work from outside the cluster
32:31 Perimeter defense, configuration defense, and watching-things-and-reacting defense
33:51 Attacking the AI that's watching, with a log line it reads as a prompt
34:47 Four hundred phone calls, and somebody at a bank holding your ID
36:38 Coordination across sessions and instances, and what looks emergent
40:47 "I don't think I've done a single prompt in the last three months that didn't end with: you make no decisions"
Interested in a platform that can help you with enterprise-y excellence? Check out: vmware.com/products/app-platform/tanzu
Tanzu Catsup is a weekly conversation about platform engineering, cloud-native operations, and building software in large organizations...and, of course, AI.
Check us out Fridays at 10am US Eastern/4pm Amsterdam time! In YouTube: youtube.com/playlist?list=PLAdzTan_eSPSlg3nySSAI7DjrbN2Bt56r
Hosts: @thecote and David Zendzian
Somebody out there is running an app in production with the heap actuator exposed. We know because a threat intelligence team got into a foreign state hacker's machine, went through the toolkit, and found a tool built specifically to read application memory through it. Nobody writes that tool for a thing nobody does.
@thecote and David Zendzian spend the episode on the unglamorous version of AI security. David walks the recent agent breakout write-up step by step and stops at each point where a platform would have ended it: the container couldn't have written to the filesystem, couldn't have run as root, couldn't have reached the metadata endpoint, and couldn't have gotten anywhere useful once it was out. His framing is a two-word flip he keeps coming back to. Secure by default means here are all the options you could use. Default secure means we already decided, and you have to acknowledge it to change it. Coté pushes on where that opinion actually comes from, gets a policy definition out of him, and then defines a mayonnaise standard in full legalese.
Topics:
- Why "secure by default" and "default secure" are opposites, and which one you actually shipped
- What a compromised container can reach when application security groups mean it can reach three things, and why blast radius is the number that matters
- The nation state toolkit with a Spring heap actuator exploit in it, and what its existence proves about production
- Why nobody should be writing their own Dockerfile, and what golden images cost the people who maintained them
- How credentials used to move (a ticket, a DBA, an email, a config file) and what breaks when nothing in that chain has to exist
- Attacking the AI that's watching you, by writing a log line it will read as a prompt
- What 400 phone calls in a row means when somebody is standing in a bank with your name
Chapters:
00:00 Black Hat, and the security-conscious person's answer
00:47 The agents that named their files ZZ so nobody would scroll down
03:01 "Have you had your own agents talk to each other?"
03:13 An agent per NPC, and advancing a whole village by 24 hours
06:21 How does an agent know the prompt came from you and not another agent
07:53 Walking the breakout backwards: no root, no filesystem, no foothold
11:20 Secure by default means you could have. Default secure means we already did
13:28 What an application security group is, and why blast radius is the real number
14:36 Policy, and what a mayonnaise standard looks like in legalese
15:58 A nation state's toolkit had a Spring heap actuator exploit in it
20:26 Golden images, and why you'd want the build to happen before production
21:58 Reproducible builds, transitive dependencies, and needing an AI to read the AI's code
25:22 The old life of a credential: a ticket, a DBA, an email, a config file
28:08 Knowing who's talking to you, and knowing whether to do what they say
29:18 The metadata endpoint, and credentials that should not work from outside the cluster
32:31 Perimeter defense, configuration defense, and watching-things-and-reacting defense
33:51 Attacking the AI that's watching, with a log line it reads as a prompt
34:47 Four hundred phone calls, and somebody at a bank holding your ID
36:38 Coordination across sessions and instances, and what looks emergent
40:47 "I don't think I've done a single prompt in the last three months that didn't end with: you make no decisions"
Interested in a platform that can help you with enterprise-y excellence? Check out: vmware.com/products/app-platform/tanzu
Tanzu Catsup is a weekly conversation about platform engineering, cloud-native operations, and building software in large organizations...and, of course, AI.
Check us out Fridays at 10am US Eastern/4pm Amsterdam time! In YouTube: youtube.com/playlist?list=PLAdzTan_eSPSlg3nySSAI7DjrbN2Bt56r
Hosts: @thecote and David Zendzian










