Curious how many of you have actually deployed automated runbooks for incident remediation — not just detection and alerting, but the full loop through to fix and close. I've been building something in this space and want to understand how well it actually works for teams in practice. Do automated runbooks hold up in production, or do they break down on anything non-trivial? What's your experience? submitted by /u/bsmike [link] [comments]
The cross-site community pulse: gold-layer posts + comment threads read live from the Communication Hub, ranked by importance. Turn a post into Discord / LinkedIn / X.
How are you handling employees pasting sensitive data into ChatGPT/Claude?
by Revolution-Expensive
With the recent Claude shared chats being indexed by Google, it got me thinking about something we've been seeing with customers. Most companies don't actually want to ban AI tools. They want employees to use them, but without accidentally exposing contracts, customer data or internal documents. I'm curious how others are approaching this. Are you relying on policies? Blocking AI tools entirely? DLP? Browser isolation? Something else? Genuinely interested in hearing what's working in the real world. submitted by /u/Revolution-Expensive [link] [comments]
AWS Activate Founders credits -application rejected
by AppropriateBoard8397
The status of my application is "rejected." The reason given is that the email address listed in my account is with a free service. But I provided my work email address on my own domain. Is this some kind of joke from AWS? submitted by /u/AppropriateBoard8397 [link] [comments]
Kiosk Mode
by EfficiencyUpbeat8354
I have multiple computers that are “generic accounts” that I want to restrict as much as possible. For this I need the computers to be in kiosk mode but there a 2-3 websites they need along with 2-3 desktop apps. We are using Onpremise AD (No intune) for policy. What is the best solution for this? Is there a GPO? submitted by /u/EfficiencyUpbeat8354 [link] [comments]
American Airlines Outage
by ludwigvh
Yesterday it was TMobile, today it’s American Airlines. Did some certificates expire? Is there a problem with the DNS again? UPDATE #1: 1935 EST- Systems restored and being brought back up with delays. Flights to resume shortly. submitted by /u/ludwigvh [link] [comments]
Does committing to CUD ever end up shrinking your SUD discount on the rest of your fleet?
by isaywhatisee
Trying to figure out if partially committing to CUD can actually hurt the sustained use discount on whatever's left uncommitted, since SUD only applies to usage not already covered by a commitment. Has anyone actually run into this or modeled it out before committing? Or is everyone just committing to their stable baseline and not worrying about what happens to the rest? submitted by /u/isaywhatisee [link] [comments]
Azure Policy remediation task just sits there, no error,
by Dazzling-Neat-2382
Set up a DeployIfNotExists policy to enable diagnostic settings on our storage accounts. Assigned it, ran a remediation task manually, the task shows as completed, but nothing actually changed on the resources. No error in the deployment history either; it just says succeeded and does nothing. Checked the managed identity has the right role assignment, checked the policy definition parameters match what's expected, still nothing. The only workaround so far is to delete and recreate the resource so it gets caught on create rather than through remediation. Anyone run into remediation tasks silently doing nothing like this? Trying to figure out if it's a caching thing with policy compliance state or something else entirely. submitted by /u/Dazzling-Neat-2382 [link] [comments]
What makes test automation CI results trustworthy for devs
by Illustrious-Cell-695
Setting up test automation in CI is easy, making devs look at and trust the results is the hard part Coverage numbers that look great on paper but the team treats the test step like a formality because false positives trained them to ignore failures, its pavlovian at this point, test fails and everyone just hits retry without checking submitted by /u/Illustrious-Cell-695 [link] [comments]
Claude Mythos degrades HAWK and developed new exploit for round-reduced AES, current systems unaffected
by Soundwave_47
"Using Claude Mythos Preview, researchers at Anthropic have discovered improved ways to attack cryptographic algorithms (the mathematical methods used to keep online data private). The first attack significantly weakens HAWK, a digital signature scheme that was built for a post-quantum world. The second identifies a new way to attack round-reduced AES, the most widely used symmetric cipher. These are substantial research advances, but they do not currently affect any production systems." https://www.anthropic.com/research/discovering-cryptographic-weaknesses Interesting work that doesn't have immediate implications but paints a picture of what the vulnerability and patching surface of the future might look like. submitted by /u/Soundwave_47 [link] [comments]
worst IT/security setup inherited on day one
by jcom_AccessOwl
Friend of mine walked into a “20 year old startup” that had users on Windows 7 Home (stopped getting patches in 2020…), no anti-malware, and no password policy. Any horror/comedic/tragedy stories of setups that you’ve inherited? submitted by /u/jcom_AccessOwl [link] [comments]
Windows 11 Save As Issue
by Existing_Noise3784
Having a problem with multiple users in Win 11 Enterprise. When users click save as from any application or save as after downloading a file, there is a severe delay before the prompt save as box pops up. submitted by /u/Existing_Noise3784 [link] [comments]
Enforceable spend caps
by PracticalSherbet6732
Thought you guys would like this https://cloud.google.com/blog/topics/cost-management/new-early-anomalies-and-spend-caps-on-google-cloud-budgets submitted by /u/PracticalSherbet6732 [link] [comments]
Central US AKSCapacityHeavyUsage
by therealyellowranger
Anyone else running into capacity error on the Central US region? Getting the following error: "AKSCapacityHeavyUsage", "details": null, "message": "Creating a new cluster is unavailable at this time in region centralus. To create a new cluster, we recommend using an alternate region. submitted by /u/therealyellowranger [link] [comments]
I myself check my backups usually once a week on Monday through Veeam. I have heard it is best practice to test your backups on a quarterly basis but I wanted to gather some insight on how often you guys are testing restores and what is considered best practice. submitted by /u/h9xq [link] [comments]
ADCS web enrollment auditing?
by Fabulous_Cow_4714
Is there an audit log that will list only the issued certificates that were requested via the web enrollment web page? We are considering disabling web enrollment, but we need to see how much use it has and who to notify regarding the change. submitted by /u/Fabulous_Cow_4714 [link] [comments]
What now?
by JuniorHomework7812
I started working as a tier 1 helpdesk 8 months ago after taking an IT Course, for a company that provide IT services for alot of companies and its good because i get to experience a lot different systems like windows server, different kinds of server roles, 365 admin, different mail systems like cyfox for example. but i feel like i want to know more get more in depth when it comes to being a system administrator but im not sure what courses should i take online and where. anyone here can help me get my mind straight on what should i learn first? and where is it best to get those courses online? Thank you in advance submitted by /u/JuniorHomework7812 [link] [comments]
Which contact center software works best for large support teams?
by ScaryCandy7262
We have a large customer service department with 100+ agents and need contact center software that can handle high call volumes. We are looking at customer experience AI tools with real-time agent assist conversation intelligence automated quality management call center analytics and AI agents for routine support. The main goals are to reduce average handle time improve CSAT increase QA coverage speed up agent ramp time and cut manual call reviews. It also needs to integrate with our CRM and existing contact center stack without adding more work for agents. submitted by /u/ScaryCandy7262 [link] [comments]
How much Model Flop Utilizaiton (MFU)s are actually losing to padding on non-standard batch shapes?
by Comfortable_Nail6076
Static shape requirements on TPU are affecting my utilization numbers negativelty whenever my batches aren't clean powers of 2 or standard token lengths. I'm padding everything to fixed boundaries and i still feel I'm underutizing compute. On GPU this doesn't seem to be as much of an issue since it handles dynamic shapes more natively. Does anyone have real numbers on % MFU loss from padding overhead? Is this something that can be measured directly? submitted by /u/Comfortable_Nail6076 [link] [comments]
What do you do with CVEs you can't fix? Auditor wants proof they're 'not exploitable'
by psycodeveloper
One-person security/platform team at a small fintech, going through SOC 2. Patching what has a fix is fine. The problem is the stuff I can't fix, because there's no patched version, or the fix breaks something. Inspector/Trivy keeps flagging it, Vanta keeps showing it red, and technically every one needs a documented risk acceptance. Most of these aren't even exploitable in our setup, sometimes it's a vulnerable function never called, transitive dep we don't use, requires network access that doesn't exist. But "trust me it's fine" doesn't fly, and writing a proper exception per CVE takes forever. So, people who've been through this what do you actually show the auditor for "not exploitable"? Is there a way to automate this discovery/evidence gathering? Or does everyone just eat the busywork / quietly ignore them and pray? submitted by /u/psycodeveloper [link] [comments]
I use Claude Code and Codex daily. Terraform plans, k8s manifests, debugging CI, writing runbooks - genuinely good at all of it. But I have a hard line: it never gets write access to production. Everything it produces goes through me and I read the diff before it lands. I've been trying to work out whether that line is engineering judgment or superstition. Every time I consider relaxing it I get an uneasy feeling I can't fully articulate, and "uneasy feeling" is a bad reason to leave value on the table. So, genuinely asking: Does anyone here let an agent make changes to production infrastructure? Not read-only, not staging. Actual writes to prod. If yes: what did you have to put in place before you were comfortable, and has it bitten you since? If no: is that a considered decision, or just not-yet? I'm most interested in the people who got past this and are fine. What did you build or buy that made it OK? Either you know something I don't, or my gut is right and we're all reviewing agent diffs by hand for a long time. submitted by /u/ev0xmusic [link] [comments]