# Framework Computer Users Are At Risk! - Threat Wire

Source: https://www.youtube.com/watch?v=S5Rspg1Pzwg
Recap page: https://rapidrecap.app/video/S5Rspg1Pzwg
Generated: 2025-10-23T13:33:47.186+00:00

---
## Quick Overview

The AWS outage on October 20th, 2025, which was the longest in history for the US-EAST-1 region, was caused by issues related to increased error rates and latencies stemming from an inadequate requirement in the internal adaptation of the ECS service responsible for searching for EC2 instances, which propagated through dependent services like DynamoDB and subsequently Network Load Balancer health checks, impacting connectivity across many AWS services until recovery was achieved, which took about half a day.

**Key Points:**
- The longest AWS outage in history occurred in the US-EAST-1 region on October 20th, 2025, beginning early morning.
- The root cause traced back to an inadequate requirement in the internal adaptation of the ECS service responsible for searching for EC2 instances.
- The issue propagated, causing increased error rates and latencies in dependent services like DynamoDB, SQS, and Lambda.
- Network Load Balancer health checks became impaired, leading to connectivity issues across many AWS services.
- AWS temporarily throttled some operations like EC2 instance launches and SQS processing during the recovery effort.
- Full service recovery took approximately half a day, with Network Load Balancer health checks recovering at 9:38 AM PDT.
- Apple announced an evolution of its Security Bounty program, increasing the maximum payout for zero-click chain attacks to $2 million.

![Screenshot at 00:20: display of the AWS Service Health dashboard detailing the 'Operational Issue - Multiple service \(N. Virginia\)' that caused the widespread outage.](https://ss.rapidrecap.app/screens/S5Rspg1Pzwg/00-00-20.png)

**Context:** The video, hosted by Ally Diamond on Threat Wire, discusses two major technology news items: the massive AWS outage in the US-EAST-1 region on October 20, 2025, detailing its cause and recovery timeline, and Apple's significant increase in its Security Bounty program payouts, particularly for zero-click chain exploits.

## Detailed Analysis

The video first covers the significant AWS outage that impacted the US-EAST-1 region on October 20th, 2025, noting it was the longest outage in AWS history. The incident began early morning due to an insufficient requirement in the internal adaptation of the ECS service, which searches for EC2 instances. This failure propagated, causing increased error rates and latencies in dependent services, including DynamoDB, SQS queues via Lambda Event Source Mappings, and asynchronous Lambda invocations. Crucially, Network Load Balancer health checks became impaired, leading to connectivity issues for many AWS services. AWS initiated recovery by temporarily throttling operations like EC2 launches and SQS processing. Network Load Balancer health checks were recovered by 9:38 AM PDT, and full service recovery took about half a day. The second segment shifts focus to Apple, which announced a major evolution of its Security Bounty program on October 10th, 2025, significantly increasing payouts to incentivize advanced security research. The maximum bounty for zero-click chain attacks that bypass Secure Boot and lead to execution was doubled from $1 million to $2 million, reflecting Apple's confidence in its defenses and its commitment to protect users targeted by mercenary spyware, such as those in civil society organizations.

### AWS US-EAST-1 Outage (Oct 20, 2025)

- Longest outage in history
- Caused by inadequate requirement in ECS internal adaptation
- Propagated to DynamoDB, SQS, and Lambda
- Network Load Balancer health checks impaired
- Recovery took about half a day

### AWS Recovery Actions

- Temporarily throttled EC2 instance launches and SQS processing
- Network Load Balancer health checks recovered by 9:38 AM PDT
- Full service recovery completed later that day

### Apple Security Bounty Increase

- Announced major evolution on Oct 10, 2025
- Max payout for zero-click chain attacks doubled to $2 million
- New max payout is $2 million, up from $1 million
- Aimed at protecting civil society from mercenary spyware

### Framework Vulnerability Disclosure

- Eclypsium researchers found a vulnerability in Framework signed UEFI shells
- The MM command allowed writing to the G Security Pointer, bypassing signature verification
- This vulnerability allows execution of unsigned components during boot, affecting Framework Laptop models

![Screenshot at 00:05: Aerial map view suggesting a geographical context, likely Washington D.C., relevant to the AWS outage discussion.](https://ss.rapidrecap.app/screens/S5Rspg1Pzwg/00-00-05.png)
![Screenshot at 00:07: A graphic displaying an eagle emblem over a globe, associated with a security or governmental/corporate entity interface.](https://ss.rapidrecap.app/screens/S5Rspg1Pzwg/00-00-07.png)
![Screenshot at 00:11: On-screen text graphic asking the central question of the first segment: 'What Brought AWS Down?'](https://ss.rapidrecap.app/screens/S5Rspg1Pzwg/00-00-11.png)
![Screenshot at 00:20: The AWS Service Health report explicitly detailing the 'Operational Issue - Multiple service \(N. Virginia\)' status as 'Resolved'.](https://ss.rapidrecap.app/screens/S5Rspg1Pzwg/00-00-20.png)
![Screenshot at 01:09: Screenshot of the AWS Service Health Page text detailing the throttling actions taken during recovery, including EC2 launches and SQS processing.](https://ss.rapidrecap.app/screens/S5Rspg1Pzwg/00-01-09.png)
![Screenshot at 01:58: On-screen text graphic introducing the second segment: 'Apple Increasing Bounty Payouts'.](https://ss.rapidrecap.app/screens/S5Rspg1Pzwg/00-01-58.png)
![Screenshot at 02:03: Screenshot of the Apple Security Research blog post titled 'A major evolution of Apple Security Bounty, with the industry's top awards for the most advanced research'.](https://ss.rapidrecap.app/screens/S5Rspg1Pzwg/00-02-03.png)
![Screenshot at 03:50: Detailed view of the Eclypsium research blog post showing the command used to identify vulnerable UEFI shells on Framework devices.](https://ss.rapidrecap.app/screens/S5Rspg1Pzwg/00-03-50.png)
![Screenshot at 04:33: Text from the Eclypsium disclosure explaining that the signed UEFI shells contained the exposed MM command that allowed bypassing signature checks.](https://ss.rapidrecap.app/screens/S5Rspg1Pzwg/00-04-33.png)
