# AWS Went Down - What Happened? Threat Wire

Source: https://www.youtube.com/watch?v=RMwUOJM7kPM
Recap page: https://rapidrecap.app/video/RMwUOJM7kPM
Generated: 2025-10-29T16:33:34.901+00:00

---
## Quick Overview

The recent AWS outage in the Northern Virginia (US-EAST-1) region was caused by three sequential failures within the Amazon DynamoDB infrastructure, specifically stemming from an outdated DynamoDB management plan that was not atomically updated, leading to cascading failures in EC2 and the Network Load Balancer service, which required manual intervention to resolve.

**Key Points:**
- The AWS outage in US-EAST-1 was a culmination of three failures across AWS infrastructure, primarily affecting DynamoDB, EC2, and the Network Load Balancer.
- The root cause involved an old DynamoDB DNS management plan that was not atomically updated, leading to inconsistent states across the system.
- The failure cascaded because EC2 instances relied on DynamoDB, and the Network Load Balancer service, which relies on EC2 instances, subsequently experienced issues due to increased latency.
- AWS did not have a recovery procedure in place for this type of massive EC2 failure, necessitating manual intervention by engineers to reset connections.
- The duration of the disruption spanned from October 19th at 11:48 PM PDT to October 20th at 2:20 PM PDT, totaling over 14 hours.
- The speaker also briefly covered a court ruling permanently barring the NSO Group from targeting WhatsApp users with Pegasus spyware, noting the ruling was based on a lack of evidence regarding the spyware's use by foreign governments.
- The speaker announced plans to build an official RSS feed reader from scratch during a future live stream to track cybersecurity news.

![Screenshot at 00:04: Satellite map overlay of Washington D.C. with red crosshairs, setting the context for the AWS US-EAST-1 region failure analysis.](https://ss.rapidrecap.app/screens/RMwUOJM7kPM/00-00-04.png)

**Context:** The video is an episode of "Threat Wire" hosted by Ali Diamond, focusing on recent high-profile technology incidents. The primary segment analyzes the root causes and cascading effects of a significant AWS service disruption that occurred in the US-EAST-1 region. A secondary, shorter segment discusses a court injunction against the NSO Group regarding its Pegasus spyware targeting WhatsApp users.

## Detailed Analysis

The recent AWS outage in the Northern Virginia (US-EAST-1) region stemmed from a complex sequence of three failures within the DynamoDB infrastructure. The initial failure involved an outdated DNS management plan that was not atomically updated, meaning some components were using the old plan while others attempted to use a new plan, creating an inconsistent state. When the system attempted its next update, it attempted to write to only one endpoint instead of all of them, overriding the newer plan. This failure cascaded to EC2 instances, which rely on DynamoDB, and subsequently affected the Network Load Balancer service, which relies on EC2 instances, leading to increased latency issues across the board. Because AWS lacked an automated recovery procedure for this level of EC2 failure, engineers had to manually intervene to reset connections to the management system. The outage lasted over 14 hours, from October 19th to October 20th. Separately, the video reported that a judge permanently barred the NSO Group from targeting WhatsApp users with Pegasus spyware, though the NSO group claims their spyware is only used by highly vetted governments. Finally, the host announced plans to build an RSS feed reader from scratch during a future live stream to track cyber news, and mentioned that OpenAI's new Atlas Browser is already vulnerable to prompt injection attacks via URLs.

### AWS DynamoDB Outage Analysis

- The outage resulted from three failures in DynamoDB infrastructure
- An old DNS management plan was not atomically updated, creating inconsistent states
- Failures cascaded to EC2 and Network Load Balancer, requiring manual engineer intervention
- Outage lasted over 14 hours (Oct 19th 11:48 PM PDT to Oct 20th 2:20 PM PDT)

### NSO Group WhatsApp Injunction

- A federal judge permanently barred NSO Group from targeting WhatsApp users with Pegasus spyware
- Meta pursued the lawsuit since 2019, alleging NSO infected about 1,400 mobile phones
- NSO asserted its spyware is only used by highly vetted governments, a claim the court ruled against.

### OpenAI Atlas Browser Vulnerability

- OpenAI announced its AI-first web browser, ChatGPT Atlas
- The browser is susceptible to prompt injection attacks via URLs that look like normal links
- This exploits the assumption that the omnibar only handles user input, not agent commands.

![Screenshot at 00:04: Satellite map overlay of Washington D.C. with red crosshairs, setting the context for the AWS US-EAST-1 region failure analysis.](https://ss.rapidrecap.app/screens/RMwUOJM7kPM/00-00-04.png)
![Screenshot at 00:05: Glitching satellite view showing initial search activity over the affected region.](https://ss.rapidrecap.app/screens/RMwUOJM7kPM/00-00-05.png)
![Screenshot at 00:06: Title card animation for "Threat Wire" program.](https://ss.rapidrecap.app/screens/RMwUOJM7kPM/00-00-06.png)
![Screenshot at 00:22: Display of the official AWS Summary of the Amazon DynamoDB Service Disruption in the Northern Virginia \(US-EAST-1\) Region, detailing the complexity of the failures.](https://ss.rapidrecap.app/screens/RMwUOJM7kPM/00-00-22.png)
![Screenshot at 01:07: Diagram illustrating DynamoDB's DNS management architecture, showing the interaction between the DNS Planner, DNS Plans, and DNS Enactors leading to Route 53.](https://ss.rapidrecap.app/screens/RMwUOJM7kPM/00-01-07.png)
![Screenshot at 03:06: News article screenshot detailing the FBI seizure of the BreachForums portal used for Salesforce extortion, serving as a transition to the second news topic.](https://ss.rapidrecap.app/screens/RMwUOJM7kPM/00-03-06.png)
![Screenshot at 04:17: News headline showing NSO permanently barred from targeting WhatsApp users with Pegasus spyware following a Meta lawsuit.](https://ss.rapidrecap.app/screens/RMwUOJM7kPM/00-04-17.png)
![Screenshot at 06:23: Article screenshot detailing the vulnerability in OpenAI's Atlas Omnibox where URLs can be interpreted as agent commands, leading to jailbreaks.](https://ss.rapidrecap.app/screens/RMwUOJM7kPM/00-06-23.png)
