Issue #117

Monday · May 08, 2023

πŸ₯— AWS security blogs

  • Get details on security finding changes with the new Finding History feature in Security Hub β€” In today’s evolving security threat landscape, security teams increasingly require tools to detect and track security findings to protect their organizations’ assets. One objective of cloud security posture management is to identify and address security findings in a timely and effective manner. AWS Security Hub aggregates, organizes, and prioritizes security …
  • Delivering on the AWS Digital Sovereignty Pledge: Control without compromise β€” At AWS, earning and maintaining customer trust is the foundation of our business. We understand that protecting customer data is key to achieving this. We also know that trust must continue to be earned through transparency and assurances. In November 2022, we announced the new AWS Digital Sovereignty Pledge, our …
  • How to scan your AWS Lambda functions with Amazon Inspector β€” Amazon Inspector is a vulnerability management and application security service that helps improve the security of your workloads. It automatically scans applications for vulnerabilities and provides you with a detailed list of security findings, prioritized by their severity level, as well as remediation instructions. In this blog post, we’ll introduce …
  • How to monitor the expiration of SAML identity provider certificates in an Amazon Cognito user pool β€” With Amazon Cognito user pools, you can configure third-party SAML identity providers (IdPs) so that users can log in by using the IdP credentials. The Amazon Cognito user pool manages the federation and handling of tokens returned by a configured SAML IdP. It uses the public certificate of the SAML …

πŸ› Reddit threads on r/aws

πŸ“Œ Newsletters

πŸ“Œ Dev.to #aws

πŸ“Œ "AWS Security" on Google News

🧁 IAM permission changes

  • appsync: 1 new condition | 1 updated action β€” 1 new condition: appsync:Visibility (Filters access by the visibility of an API); 1 updated action: CreateGraphqlApi (conditions)
  • route53resolver: 7 updated actions β€” 7 updated actions: AssociateResolverEndpointIpAddress (dependents), AssociateResolverRule (dependents), CreateResolverEndpoint (dependents), DeleteResolverEndpoint (dependents), DisassociateResolverEndpointIpAddress (dependents), ListResolverRuleAssociations (dependents), UpdateResolverEndpoint (dependents)
  • elasticfilesystem: 1 new condition | 1 updated action β€” 1 new condition: elasticfilesystem:CreateAction (Filters access by the name of a resource-creating API action); 1 updated action: TagResource (conditions)

πŸͺ API changes

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.