SRE Weekly Issue #354 • [tl;dr sec] #163 - Rebuilding Detection and IR at LinkedIn, CVEs and Misaligned Incentives • AWS Audit Manager - 2 updated methods • AmplifyBackend - 1 updated methods • AWS App Runner - 6 updated methods • Amazon Connect Service - 2 updated methods • How to query and visualize Macie sensitive data discovery results with Athena and QuickSight • Updated whitepaper available: AWS Security Incident Response Guide • ec2: 29 updated actions, 7 updated conditions • iotroborunner: 29 removed actions, 5 removed resources, 5 removed conditions • autoscaling: 1 updated action • Amazon S3 Encrypts New Objects By Default | Amazon Web Services • I scanned every package on PyPi and found 57 live AWS keys • Why Not Mars • Update detected · z0ph/MAMIP@067b455 • *screaming in cloud security* <a href="https://t.co/rjPV81wYxT" target="_blank">tomforb.es/i-scanned-ever…</a> • S3 at rest encryption by default and soon it'll be non-trivial to make an S3 bucket public because Public Block access will be applied by default in April. We also got multiple MFAs for the root and the root email no longer tied to the underpants account. Thank you AWS folks! • If S3 is going to encrypt all objects by default, what are we going to argue about now? (Welcome move, one less dimension for customers to misconfigure) <a href="https://t.co/MDi6nLR4WM" target="_blank">aws.amazon.com/blogs/aws/amaz…</a> • ☁️ Cloud penetration testing: Not your typical internal penetration test <a href="https://twitter.com/sethsec" target="_blank">@sethsec</a> walks through how doing an internal (assume breach) cloud pen test is different than a typical pen test, with examples of increasingly useful things to look for <a href="https://t.co/vUvmhWFdX1" target="_blank">sethsec.blogspot.com/2022/12/cloud-…</a> • How about another real world attacker critique thread? <a href="https://twitter.com/ExpelSecurity" target="_blank">@ExpelSecurity</a> just published a great piece on an intrusion they took care of (Great work team). A thread. 🧵 <a href="https://t.co/KUeV8fdjtz" target="_blank">expel.com/blog/incident-…</a> • another year and still no fucking idea how to use mastodon • Devs: make it your new years resolution to serve OPTIONS at the edge. Your users in Australia and India will thank you. (It's very painful to use a modern SPA webapp and have dozens of round-trips each take an extra 250ms just for the preflights) <a href="https://t.co/Cu5myEqOHr" target="_blank">aws.amazon.com/blogs/networki…</a> • It's a small thing but the SEC opting not to refer to Elon Musk, even obliquely, as a founder of Tesla is hilarious (from <a href="https://twitter.com/matt_levine" target="_blank">@matt_levine</a>'s always excellent Money Stuff) • 😈 Attacker persistence in <a href="https://twitter.com/hashtag/Kubernetes" target="_blank">#Kubernetes</a> using the TokenRequest API The TokenRequest API can be used to create long-lived and hard-to-detect privileged access <a href="https://twitter.com/raesene" target="_blank">@raesene</a> on how attackers can abuse it &amp; how to detect misuse by monitoring k8s audit logs <a href="https://t.co/7Qeeh9szp5" target="_blank">securitylabs.datadoghq.com/articles/kuber…</a> • AWS Lambda function URLs + CloudFront is a pretty great combination. I've got a custom domain, TLS-enabled, WAF-protected, nearly-infinitely-scalable endpoint for like... $0.05/month. • Amazon S3 Encrypts New Objects By Default | Amazon Web Services • My Infrastructure as Code Rosetta Stone - Deploying the same web application on AWS ECS Fargate with CDK, Terraform and Pulumi • Updated whitepaper available: AWS Security Incident Response Guide • Amazon Neptune announces graph-explorer, an open-source visual exploration tool for low-code users • Amazon S3 will now encrypt all new data with AES-256 by default - BleepingComputer • Ring Car Cam extends Amazon's security footprint further beyond ... - GeekWire • AWS IP Ranges update for 2022-12-27 23:43:05 • AWS IP Ranges update for 2022-12-28 00:23:06

ASD Logo

9
Monday January, 2023

Sponsor

New Year, same AWS IAM headache? 😣

What if you could find and fix your critical IAM issues in less than 30 days?

What if it was also free and easy for your whole team to use?

k9 Security’s Starter Plan is available at no cost for ASD subscribers all month!

Start fixing IAM today

In a nutshell

Today marks a significant occasion for ASD with the release of the 100th issue of the newsletter.

The newsletter started as a personal collection of AWS security news but has now grown to have over 1500 subscribers following updates on a weekly basis. Additionally, the newsletter has secured recurring sponsorships from partners.

We are incredibly grateful for the support and readership of the newsletter so far. If you have enjoyed reading the newsletter, please consider spreading the word to others who may also be interested.

Your support helps us to continue bringing you the latest updates on AWS security.

AWS Audit Manager - 2 updated methods
Jan 6
This release introduces a new data retention option in your Audit Manager settings. You can now use the DeregistrationPolicy parameter to specify if you want to delete your data when you deregister Audit Manager.
AmplifyBackend - 1 updated methods
Jan 5
Updated GetBackendAPIModels response to include ModelIntrospectionSchema json string
AWS App Runner - 6 updated methods
Jan 5
This release adds support of securely referencing secrets and configuration data that are stored in Secrets Manager and SSM Parameter Store by adding them as environment secrets in your App Runner service.
Amazon Connect Service - 2 updated methods
Jan 5
Documentation update for a new Initiation Method value in DescribeContact API
How to query and visualize Macie sensitive data discovery results with Athena and QuickSight
Keith RozarioJan 6
Amazon Macie is a fully managed data security service that uses machine learning and pattern matching to help you discover and protect sensitive data in Amazon Simple Storage Service (Amazon S3). With Macie, you can analyze objects in your S3 buckets to detect occurrences of sensitive data, such as personally identifiable information (PII), financial information, personal …
Updated whitepaper available: AWS Security Incident Response Guide
Anna McAbeeJan 4
The AWS Security Incident Response Guide focuses on the fundamentals of responding to security incidents within a customer’s Amazon Web Services (AWS) Cloud environment. You can use the guide to help build and iterate on your AWS security incident response program. Recently, we updated the AWS Security Incident Response Guide …
ec2: 29 updated actions, 7 updated conditions
Jan 7
29 updated actions: AuthorizeSecurityGroupEgress (resources), AuthorizeSecurityGroupIngress (resources), DescribeClientVpnAuthorizationRules (resources), DescribeClientVpnConnections (resources), DescribeClientVpnRoutes (resources), DescribeClientVpnTargetNetworks (resources), DescribeFleetHistory (resources), DescribeFleetInstances (resources), DescribeImageAttribute (resources), DescribeInstanceAttribute (resources), DescribeSnapshotAttribute (resources), DescribeSpotFleetInstances (resources), DescribeSpotFleetRequestHistory (resources), DescribeVolumeAttribute (resources), DisableAddressTransfer (resources), DisableFastLaunch (resources), EnableAddressTransfer (resources), EnableFastLaunch (resources), GetCoipPoolUsage (resources), GetConsoleScreenshot (resources), GetVpnConnectionDeviceSampleConfiguration (resources), ModifyInstanceCapacityReservationAttributes (resources), ModifySecurityGroupRules (resources), MoveByoipCidrToIpam …
iotroborunner: 29 removed actions, 5 removed resources, 5 removed conditions
Jan 6
29 removed actions: CreateAction (Grants permission to create an action), CreateActionTemplate (Grants permission to create an action template), CreateActionTemplateDependency (Grants permission to create an action template dependency), CreateActivity (Grants permission to create an activity), CreateActivityDependency (Grants permission to create an activity dependency), CreateDestinationRelationship (Grants permission to create a destination relationship), …
autoscaling: 1 updated action
Jan 6
1 updated action: CreateAutoScalingGroup (conditions)
0xdabbad00
Scott Piper @0xdabbad00

S3 at rest encryption by default and soon it'll be non-trivial to make an S3 bucket public because Public Block access will be applied by default in April. We also got multiple MFAs for the root and the root email no longer tied to the underpants account. Thank you AWS folks!

20Jan 05 · 11:39 PM
__steele
Aidan W Steele @__steele

If S3 is going to encrypt all objects by default, what are we going to argue about now? (Welcome move, one less dimension for customers to misconfigure)

aws.amazon.com/blogs/aws/amaz…

10Jan 05 · 10:54 PM
clintgibler
Clint Gibler @clintgibler

☁️ Cloud penetration testing: Not your typical internal penetration test

@sethsec walks through how doing an internal (assume breach) cloud pen test is different than a typical pen test, with examples of increasingly useful things to look for

sethsec.blogspot.com/2022/12/cloud-…

24Jan 06 · 5:00 PM
Frichette_n
Nick Frichette - @frichetten@fosstodon.org @Frichette_n

How about another real world attacker critique thread? @ExpelSecurity just published a great piece on an intrusion they took care of (Great work team). A thread. 🧵 expel.com/blog/incident-…

24Jan 07 · 2:33 AM
abbyfuller
Abby Fuller @abbyfuller

another year and still no fucking idea how to use mastodon

4Jan 03 · 2:23 AM
__steele
Aidan W Steele @__steele

Devs: make it your new years resolution to serve OPTIONS at the edge. Your users in Australia and India will thank you.

(It's very painful to use a modern SPA webapp and have dozens of round-trips each take an extra 250ms just for the preflights)

aws.amazon.com/blogs/networki…

10Jan 06 · 1:29 AM
ben11kehoe
Ben Kehoe @ben11kehoe

It's a small thing but the SEC opting not to refer to Elon Musk, even obliquely, as a founder of Tesla is hilarious (from @matt_levine's always excellent Money Stuff)

2Jan 06 · 9:36 PM
clintgibler
Clint Gibler @clintgibler

😈 Attacker persistence in #Kubernetes using the TokenRequest API

The TokenRequest API can be used to create long-lived and hard-to-detect privileged access

@raesene on how attackers can abuse it & how to detect misuse by monitoring k8s audit logs

securitylabs.datadoghq.com/articles/kuber…

13Jan 06 · 9:00 PM
matthewdfuller
Matt Fuller @matthewdfuller

AWS Lambda function URLs + CloudFront is a pretty great combination. I've got a custom domain, TLS-enabled, WAF-protected, nearly-infinitely-scalable endpoint for like... $0.05/month.

0Jan 02 · 9:40 PM
AWS IP Ranges update for 2022-12-27 23:43:05
Changed by -16

Removed 3.33.49.240/30
Removed 52.46.189.36/30
Removed 52.46.189.40/30
Removed 52.46.191.108/30
AWS IP Ranges update for 2022-12-28 00:23:06
Changed by -32

Removed 3.33.49.136/29
Removed 3.33.49.192/29
Removed 3.33.49.132/30
Removed 3.33.49.144/30
Removed 3.33.49.164/30
Removed 3.33.49.180/30