366: You just can’t kill a good JWT

Episode 366 August 12, 2026 01:01:21
366: You just can’t kill a good JWT
The Cloud Pod | Weekly AI & Cloud News on AWS, Azure & GCP
366: You just can’t kill a good JWT

Aug 12 2026 | 01:01:21

/

Hosted By

Jonathan Baker Justin Brodley Matthew Kohn Ryan Lucas

Show Notes

Welcome to episode 366 of The Cloud Pod, where the forecast is always cloudy! Ryan is back from “vacation,” aka his other job (moonlighting as the admin of the Eagles’ biggest fan Facebook group), and this week we’re talking a lot about security, how orgs are managing threats, and whose turn it is to release a new hoard of patches. Plus, we’ve got news from BigQuery, JWT, MCP, and Cloudflare – and so much more, so let’s get started! 

Titles we almost went with this week

A big thanks to this week’s sponsors:

We’re sponsorless! Want to get your brand, company, or service in front of a very enthusiastic group of cloud news seekers? You’ve come to the right place! Send us an email or hit us up on our Slack channel for more info.

General News 

It’s Earnings Time! 

01:12 Google (GOOG) Q2 2026 earnings report: Live updates

04:19 AWS earnings Q2 2026

06:22 Microsoft (MSFT) Q4 earnings report 2026

06:22 Justin – “So overall, no one is buying hardware right now, because it’s way too expensive.”  

AI Is Going Great – or How ML Makes Money 

09:53 With a stateless makeover, new MCP spec targets enterprise scale

12:56 Ryan – “It is interesting how big of a change this is; if you already have an application out there, this is a big rewrite. You cannot just drop this in.”  

13:23 Amazon accidentally spent $1.8 million using Claude for menial coding task, went 860% over budget — ‘catastrophically expensive’ coding 

blunders discovered in internal Amazon AI usage metrics

14:21 Justin – “If Amazon can’t get this right, how am I going to do it right?” 

Security

17:04 Apple caps security bug reports amid surge in AI-generated findings

18:54 Justin – “To totally cap getting them at all seems like a really silly way to try and control this problem.” 

20:23 Amazon identifies North Korean hacker group behind open-source supply chain attacks

Cloud Tools 

23:03 Stacked pull requests are now in public preview

AWS 

26:57 A bigger role for Swami: Amazon’s agentic AI chief gets broader mandate to shape emerging tech 

27:57 Ryan – “I’m still stuck on trying to figure out what Neurosymbolic AI is.” 

29:38 Authenticate with Private Key JWT using Amazon Bedrock AgentCore Identity

30:41 Ryan – “So while MCP is moving towards OAuth and client secrets, this is moving away.” 

32:15 Balancing speed and safety: A control framework for AI coding agents

35:36 AWS WAF adds pre-parse text transformations and new text transformations

36:371 Ryan – “Cloud native WAFs – actually all WAFs – are becoming VERY complicated.” 

39:51 AWS Organizations now provides maximum account quota visibility in Service Quotas

41:55 Introducing Web Search on Amazon Bedrock for foundation model grounding

42:52 Justin – “So I’m very happy this exists, because one of the problems you have with Bedrock Agents is that they don’t know anything about the web. They don’t know what the date is, and you had to provide it with a bunch of updated information and context if you need it to be anything current; and so the fact that it has some ability to do this, maybe not completely what you need, but at least it’s heading in the right direction.”

GCP

44:31 Cloud CISO Perspectives: Why AI Threat Defense is the new boardroom baseline

45:41 Justin – “Thanks, Google, for scaring the board, and then giving us some new tools.”  

46:55 Introducing the borderless Lakehouse 

50:42 Deep dive on new AI-powered database agents 

Azure

52:23 Public Preview: Route-Maps for Azure Route Server

54:10 Generally Available: Trusted Launch as Default

54:46 Justin – “That this isn’t required in 2026 is kind of blowing my mind…” 

Oracle 

55:30  Oracle to Make Gemini Models Available to Thousands of Enterprise Applications Customers

55:51 Justin – “That’s nice. Can’t wait to get Gemini terribleness in my fusion apps.” 

Emerging Clouds

56:45 Your agent needs a computer, not a container — introducing @cloudflare/computer

59:15 Introducing: Cloudflare Agents

1:00:4 Introducing the Billable Usage API: programmatic cost visibility for Cloudflare

Closing

And that is the week in the cloud! Visit our website, the home of the Cloud Pod, where you can join our newsletter, Slack team, send feedback, or ask questions at theCloudPod.net or tweet at us with the hashtag #theCloudPod

Other Episodes

Episode

March 17, 2019 1h03m36s
Episode Cover

Episode 14: Elizabeth Warren votes to break up the cloud pod

This week Matt Adorjan (@mda590) joins us to talk about AWS’s open distro for ElasticSearch, Breaking up big tech, and F5 acquiring Nginx. Plus...

Listen

Episode 243

January 17, 2024 00:30:17
Episode Cover

243: WHOIS The Cloud Pod? We’ll Never Know

Welcome to episode 243 of the Cloud Pod podcast – where the forecast is always cloudy! It’s a bit of a slow new week,...

Listen

Episode 258

May 10, 2024 01:02:14
Episode Cover

258: To Q or Not to Q – That is the Question (But, Will We Get a Good Answer?)

Welcome to episode 258 of the Cloud Pod podcast – where the forecast is always cloudy! This week your hosts Justin, Matthew, and Jonathan...

Listen