Security Newsletter - GPT to help out in security matters. Exchange will block mail from vulnerable on-prem servers. Ultrasound control over digital assistants. • AWS Notification Message • [tl;dr sec] #175 - The Future of Security Engineering, Awesome Kubernetes Threat Detection • AWS Notification Message • Auto Scaling - 10 updated methods • AWS Batch - 1 updated methods • AWS Compute Optimizer - 4 updated methods • Simplify web app authentication: A guide to AD FS federation with Amazon Cognito user pools • Gain insights and knowledge at AWS re:Inforce 2023 • The National Intelligence Center of Spain and AWS collaborate to promote public sector cybersecurity • How to use Amazon GuardDuty and AWS WAF v2 to automatically block suspicious hosts • guardduty: 3 new actions • finspace: 1 updated condition • applicationinsights: 1 new action • Exploring Amazon VPC Lattice – One Cloud Please • RFC: AppSync abstraction for SAM · aws/serverless-application-model · Discussion #3075 • 😈 Fun with SSRF - Turning the Kubernetes API Server into a port scanner <a href="https://twitter.com/raesene" target="_blank">@raesene</a> shows how to leverage existing functionality on <a href="https://twitter.com/hashtag/Kubernetes" target="_blank">#Kubernetes</a> to perform scans from the API server using validating admission webhooks 🛠️ PoC <a href="https://t.co/OxkeUgeeus" target="_blank">github.com/raesene/k8s_ss…</a> <a href="https://t.co/KPorUqEZRe" target="_blank">raesene.github.io/blog/2023/01/0…</a> • 🔎 awesome-detection-rules A collection of threat detection rules / rules engines, including: * Yara * Sigma * Falco * Zeek * Snort/Suricata * Splunk + more By <a href="https://twitter.com/jason_trost" target="_blank">@jason_trost</a> <a href="https://twitter.com/hashtag/infosec" target="_blank">#infosec</a> <a href="https://twitter.com/hashtag/blueteam" target="_blank">#blueteam</a> <a href="https://t.co/HAsBQKkeWn" target="_blank">github.com/jatrost/awesom…</a> • Gross. Unverify us you coward. • Check out my new post on the newly GA'd <a href="https://twitter.com/hashtag/AWS" target="_blank">#AWS</a> <a href="https://twitter.com/hashtag/Amazon" target="_blank">#Amazon</a> VPC Lattice service! 📝🌐 <a href="https://t.co/jlP5SNzpzG" target="_blank">onecloudplease.com/blog/exploring…</a> • TIL that Go Lambda functions now have a nice way to perform cleanup without ugly workarounds. • 🪣"practical guidance for your AWS security program": <a href="https://t.co/sSx2zJEG7U" target="_blank">ramimac.me/s3-logging</a> 🪣 This time, we're tackling S3 Logging! As one of the foundational services, I expected "best practices for s3 logging" to be well established. I was disappointed ... • To answer <a href="https://twitter.com/QuinnyPig" target="_blank">@QuinnyPig</a>'s question: I implemented something like this, and I want to implement it again. IMO, enriched VPC flow logs are an untapped source of extremely valuable data. I just don't have access to realistic training data and need help. Blog: <a href="https://t.co/yef7Lh6N8W" target="_blank">awsteele.com/blog/2021/05/1…</a> • New research from <a href="https://twitter.com/wiz_io" target="_blank">@wiz_io</a>! Customers with the misconfiguration identified will need to take action! • I have a feeling every single person in the room with Elon when he made this pricing decision knew it would be met with the Arrested Development banana meme, but was too afraid to speak up • Amazon Fights Oregon Clean Energy Bill • Aws reps keep pushing a specific vendor on me • Amazon VPC Lattice now GA! • TLS 1.3 with ELB and ALB: The Wait is Over! • Elastic Unveils Advanced Cloud Security Solutions for AWS Users - Read IT Quik • Elastic Unfurls Cloud Security Platform for AWS - Security Boulevard

ASD Logo

3
Monday April, 2023

📣 Sponsor

Unburden security specialists using your product!

Simplify your AWS access management workflows and event analysis with k9 Security's cloud access management toolkit.

Learn how to integrate scalable identity entitlement management into your MSSP, MDR/XDR, CNAPP, or CloudOps service:

👉 https://www.k9security.io/lp/integrate-ciem

🐿 In a nutshell

This week, I'll be sharing some valuable information about AWS Security: Look out for insights on VPC Lattice, now available as GA, an informative paper on S3 Logging, and a great slide deck on AWS Pentesting.

I also came across a fascinating paper by Dylan Patel from SemiAnalysis, discussing AWS's silicon strategy and the potential risks for Amazon's future in computing.

Don't forget, I'll be attending the AWS Summit in Paris tomorrow. If you're a French reader, I'd love to meet you there! Let's chat about all things AWS.

Auto Scaling - 10 updated methods
Mar 30
Amazon EC2 Auto Scaling now supports Elastic Load Balancing traffic sources with the AttachTrafficSources, DetachTrafficSources, and DescribeTrafficSources APIs. This release also introduces a new activity status, "WaitingForConnectionDraining", for VPC Lattice to the DescribeScalingActivities API.
AWS Batch - 1 updated methods
Mar 30
This feature allows Batch on EKS to support configuration of Pod Labels through Metadata for Batch on EKS Jobs.
AWS Compute Optimizer - 4 updated methods
Mar 30
This release adds support for HDD EBS volume types and io2 Block Express. We are also adding support for 61 new instance types and instances that have non consecutive runtime.
Simplify web app authentication: A guide to AD FS federation with Amazon Cognito user pools
Leo DrakopoulosMar 31
August 13, 2018: Date this post was first published, on the Front-End Web and Mobile Blog. We updated the CloudFormation template, provided additional clarification on implementation steps, and revised to account for the new Amazon Cognito UI. User authentication and authorization can be challenging when you’re building web and mobile …
Gain insights and knowledge at AWS re:Inforce 2023
CJ MosesMar 30
I’d like to personally invite you to attend the Amazon Web Services (AWS) security conference, AWS re:Inforce 2023, in Anaheim, CA on June 13–14, 2023. You’ll have access to interactive educational content to address your security, compliance, privacy, and identity management needs. Join security experts, peers, leaders, and partners from …
The National Intelligence Center of Spain and AWS collaborate to promote public sector cybersecurity
Borja LarrumbideMar 30
Spanish version » The National Intelligence Center and National Cryptological Center (CNI-CCN)—attached to the Spanish Ministry of Defense—and Amazon Web Services (AWS) have signed a strategic collaboration agreement to jointly promote cybersecurity and innovation in the public sector through AWS Cloud technology. Under the umbrella of this alliance, the CNI-CCN …
How to use Amazon GuardDuty and AWS WAF v2 to automatically block suspicious hosts
Eucke WarrenMar 29
In this post, we’ll share an automation pattern that you can use to automatically detect and block suspicious hosts that are attempting to access your Amazon Web Services (AWS) resources. The automation will rely on Amazon GuardDuty to generate findings about the suspicious hosts, and then you can respond to …
guardduty: 3 new actions
Apr 1
3 new actions: GetCoverageStatistics (Grants permission to list Amazon GuardDuty coverage statistics for the specified GuardDuty account in a Region), ListCoverage (Grants permission to list all the resource details for a given account in a Region), SendSecurityTelemetry (Grants permission to send security telemetry for a specific GuardDuty account in a …
finspace: 1 updated condition
Apr 1
1 updated condition: aws:TagKeys (type)
applicationinsights: 1 new action
Apr 1
1 new action: Link (Grants permission to share Application Insights resources with a monitoring account)
clintgibler
Clint Gibler @clintgibler

😈 Fun with SSRF - Turning the Kubernetes API Server into a port scanner

@raesene shows how to leverage existing functionality on #Kubernetes to perform scans from the API server using validating admission webhooks

🛠️ PoC
github.com/raesene/k8s_ss…

raesene.github.io/blog/2023/01/0…

34Mar 31 · 7:00 PM
clintgibler
Clint Gibler @clintgibler

🔎 awesome-detection-rules

A collection of threat detection rules / rules engines, including:
* Yara
* Sigma
* Falco
* Zeek
* Snort/Suricata
* Splunk

+ more

By @jason_trost

#infosec #blueteam

github.com/jatrost/awesom…

24Mar 28 · 7:00 PM
iann0036
Ian Mckay @iann0036

Check out my new post on the newly GA'd #AWS #Amazon VPC Lattice service! 📝🌐

onecloudplease.com/blog/exploring…

17Apr 01 · 1:07 PM
__steele
Aidan W Steele @__steele

TIL that Go Lambda functions now have a nice way to perform cleanup without ugly workarounds.

5Mar 29 · 8:28 AM
ramimacisabird
rami @ramimacisabird

🪣"practical guidance for your AWS security program": ramimac.me/s3-logging 🪣

This time, we're tackling S3 Logging! As one of the foundational services, I expected "best practices for s3 logging" to be well established. I was disappointed ...

16Mar 29 · 10:19 PM
__steele
Aidan W Steele @__steele

To answer @QuinnyPig's question: I implemented something like this, and I want to implement it again. IMO, enriched VPC flow logs are an untapped source of extremely valuable data. I just don't have access to realistic training data and need help. Blog:
awsteele.com/blog/2021/05/1…

10Mar 28 · 3:29 AM
0xdabbad00
Scott Piper @0xdabbad00

New research from @wiz_io! Customers with the misconfiguration identified will need to take action!

hillai
Hillai Ben-Sasson @hillai

I hacked into a @bing CMS that allowed me to alter search results and take over millions of @Office365 accounts.
How did I do it? Well, it all started with a simple click in @Azure… 👀
This is the story of #BingBang 🧵⬇️

7Mar 29 · 8:47 PM
ben11kehoe
Ben Kehoe @ben11kehoe

I have a feeling every single person in the room with Elon when he made this pricing decision knew it would be met with the Arrested Development banana meme, but was too afraid to speak up

TwitterDev
Twitter Dev @TwitterDev

We are also launching a new Basic (v2) access for hobbyists with 10,000 GET/month and 50,000 POST/month, 2 app IDs, and Login with Twitter for $100/month.

Subscribe now: developer.twitter.com/en/portal/prod…

12Mar 30 · 9:34 PM
Amazon Fights Oregon Clean Energy Bill

https://www.oregonlive.com/business/2023/03/amazon-fights-oregon-data-center-clean-energy-bill.html

But what about the new sustainability pillar!!?!?!?!

Shit like this is the exact reason I say that their things like the "Sustainability Pillar" are pure bullshit.

I love you to death AWS. But don't pretend you care about the environment. You're a big corporate machine with one goal: To …

Aws reps keep pushing a specific vendor on me

Two aws reps with Amazon.com email addresses contacted me. They keep trying to push a well-architected review. They claim they have a specific vendor in mind for me. I told them that I was not interested, but then they tried to get me to install a tool that appears to …

Amazon VPC Lattice now GA!

Amazon VPC Lattice is an application networking service that consistently connects, monitors, and secures communications between your services, helping to improve productivity so that your developers can focus on building features that matter to your business. You can define policies for network traffic management, access, and monitoring to connect compute …

TLS 1.3 with ELB and ALB: The Wait is Over!

Our application is hosted on Elastic Beanstalk and we've been trying to select one of the TLS 1.3 security policies in the management console. However, we've been consistently receiving an error message stating that the policy is not supported. This has been a frustrating experience for us, as we know …

  • 🖊️ Don't miss out on the latest industry insights - stay ahead of the game by subscribing
  • 📢 Gain visibility for your brand by sponsoring our content
  • 💌 If you have any suggestions for future topics, let us know