The HashWhales Dispatch

Software, security, and cloud news — summarized in plain language, with sources.

AWS and Cloudflare expand access controls with dashboard tags and open OAuth

AWS adds tagging support to CloudWatch dashboards while Cloudflare opens its OAuth engine to all developers, both moves widening governance and integration options.

Cordyceps CI/CD Flaw Hits 300+ Repos; Scattered Spider Members Plead Guilty

A newly named GitHub workflow vulnerability threatens major open-source supply chains while two high-profile cybercriminals admit guilt in a UK court.

DoJ Seizes Huione Cloud Account; Scattered Spider Members Plead Guilty

Two major cybercrime enforcement actions in a single week signal mounting pressure on transnational fraud networks and organized hacking groups.

AWS adds agentless syslog ingestion; U.S. EO sets 2030 post-quantum deadline

Two infrastructure moves signal tightening network visibility and encryption requirements for organizations running on cloud and government-adjacent systems.

FortiBleed Exposes 110M Credentials; Scattered Spider Members Plead Guilty

A sweeping firewall credential-harvesting campaign and a landmark cybercrime guilty plea mark a turbulent week for enterprise security.

GitHub Patches CI/CD Exploit Vector; Android Botnet Tied to Israeli Proxy Firm

Two cybersecurity developments expose risks in open-source pipelines and consumer device ecosystems that directly affect enterprise security posture.

GitHub exec runs on 40 automations; Vercel adds custom OIDC token audiences

Two developer-platform updates this week push automation deeper into leadership workflows and tighten security controls for CI/CD pipelines.

Rogue npm Packages and a Four-Year Android Botnet Expose Supply Chain Risks

Two separate investigations reveal how attackers are hiding malicious code inside developer tools and consumer hardware to conduct fraud and espionage at scale.

AWS HealthOmics gains Nextflow profile support; Cloudflare exposes hyper HTTP bug

Two networking-adjacent updates this week highlight infrastructure flexibility and open-source vulnerability discovery in production environments.

Vercel Links Claude AI Design Tool to Deployments; GitHub Pushes Accessibility

Vercel now lets developers ship Claude-generated designs directly to production, while GitHub advances its accessibility commitments across the open source ecosystem.

AWS tightens firewall defaults; Cloudflare exposes hyper HTTP library bug

Two infrastructure developments this week signal heightened attention to reliability gaps in foundational networking layers.

WordPress Plugin Backdoor and Android Botnet Expose Supply Chain Risks

Two separate incidents this week reveal how compromised software pipelines and consumer hardware are being weaponized against businesses at scale.

Signal, not noise

Technology news translated into business decisions

The HashWhales Dispatch follows cybersecurity incidents, software releases, artificial intelligence, cloud infrastructure, and the policy changes that affect modern organizations. Each brief links to its original sources and explains why the development matters, without turning a press release into a prediction. The goal is to help owners and technical leaders decide what deserves attention now, what can wait, and what should change in their systems.

For deeper implementation guidance, visit our engineering insights. If a story raises a question about your own website, network, backups, or security posture, request a free technology risk review for a practical, company-specific next step.

Free AuditChat on WhatsApp