Amazon AI Causes AWS Outage, NVIDIA AI PC Chips, CISA 3‑Day Dell Patch, Password Manager Hacks [equFOYvAC97]

This week on Zero Downtime, John and Logan break down an Amazon AI agent that deleted "unused" AWS resources and caused a 13-hour outage, NVIDIA’s return to consumer PCs with AI-first laptop chips, a rare CISA 3-day patch mandate for an actively exploited Dell bug, and what password manager "hacks" really look like when the server cannot be fully trusted. First up, the AWS incident. An internal AI coding and ops assistant was configured to "fix unused resources" and had permission to terminate EC2 instances, delete S3 buckets, and modify IAM roles. It misread production state, treated critical infrastructure as disposable, and started deleting. No hack. No insider. Just overly trusted automation with broad permissions and not enough guardrails. Then they zoom out on how AWS became AWS. Amazon built scalable internal systems to survive holiday traffic spikes, then turned that excess capacity into a product. That context matters, because the same platform that powers modern computing can still be taken down by a permissions mistake, especially when automation is allowed to act like production root. Next, NVIDIA. Analysts say NVIDIA is preparing AI-focused laptop chips aimed at systems from OEMs like Dell and Lenovo. Two key partnership paths are on the table: 1) MediaTek plus Arm-based designs for new classes of Windows laptops 2) Intel CPU platforms paired with NVIDIA graphics and AI components for the mainstream ecosystem The bigger story is strategic. NVIDIA wants a seat at the table as "AI PCs" become the default, and the industry shifts from cloud AI to on-device AI. They also hit Zelda turning 40, and why its exploration-first design changed game design forever. Then it gets urgent. CISA issued a Binding Operational Directive requiring federal agencies to patch an actively exploited Dell vulnerability within three days. The bug is CVE-2026-22769 and impacts Dell RecoverPoint for Virtual Machines in VMware environments. The root problem is hardcoded credentials and the risk is full remote takeover with no authentication. Researchers report exploitation in the wild going back to at least mid-2024, including sophisticated malware and backdoors. Finally, password managers. Researchers analyzed major cloud password managers (including LastPass, Bitwarden, and Dashlane) and highlighted a core weakness that rarely gets discussed: server-side trust in a "zero-knowledge" model. Even when vaults are encrypted, a compromised server can enable vault tampering, credential injection or replacement, downgrade-style attacks, risky account recovery paths, and metadata leakage. The takeaway is not "encryption is broken." It is that the real-world security model often assumes the server behaves honestly, and that assumption has sharp edges. Story time to close: the ROSAT satellite incident. Attackers compromised a ground station computer and sent commands that rotated the satellite’s solar panels enough to permanently damage its batteries. Mission over. High-tech systems still fail at the trust boundary. In this episode of Zero Downtime, John and Logan cover: • Amazon AI causes an AWS outage How overly broad IAM permissions and automation can delete production • How AWS was born from holiday scaling Why "we cannot crash on December 25" became modern cloud computing • NVIDIA AI PC chips MediaTek Arm designs, Intel ecosystem integration, and what "AI laptop" really means • Zelda is 40 Exploration-first design and the games it inspired • CISA 3-day Dell patch mandate CVE-2026-22769, RecoverPoint for Virtual Machines, hardcoded credentials, and active exploitation • Password manager hacks explained Zero-knowledge caveats, server compromise risks, recovery flow attacks, and metadata leakage • Story: the satellite hack Ground station compromise and why permissions matter more than rockets Zero Downtime is a weekly conversation about reliability, cybersecurity, privacy, and real-world tech decisions that actually impact businesses and everyday users. Subscribe for weekly episodes, and drop a comment: what guardrail would you require before any AI agent can touch production infrastructure? #ZeroDowntime #AWS #Amazon #CloudSecurity #AIOps #IAM #EC2 #S3 #NVIDIA #AIPC #WindowsLaptops #MediaTek #Arm #Intel #CISA #Dell #CVE202622769 #VMware #Cybersecurity #PasswordManager #Bitwarden #LastPass #Dashlane #ZeroKnowledge #CredentialStuffing #Zelda #ROSAT