SRE Weekly Issue #263
📖 [The CloudSecList] Issue 80
AWS Security Hub integrates with Amazon Macie to automatically ingest sensitive data findings for improved centralized security posture management
How to automate SCAP testing with AWS Systems Manager and Security Hub
How to implement the principle of least privilege with CloudFormation StackSets

"Yesterday (2021-03-28), two malicious commits were pushed to the php-src repo [...]. We don't yet know how
exactly this happened, but everything points towards a compromise of the git.php.net server"
👀
news-web.php.net/php.internals/…




Uh, there is no Cloudtrail record of AWS applying this policy! 🤬 I know it was applied because it did break a workflow (this key was used by a level of flaws.cloud, no errors a few days ago, then access denieds). If you add a policy to my IAM user, please log it AWS.

AWS has started adding an inline policy to deny s3:* on compromised access keys in addition to their quarantine policy which is more focused on stopping bitcoin miners. This has the potential for greater customer impact but exfil is what companies tend to be more concerned about.



I kept telling you all these complex container things were gonna cause a problem. But no. Ya'll wanted to put k8s on your resume. Well now the Suez Canal is blocked. Good job.



I checked the account and saw the new policy, and the access denieds on s3:ListBuckets calls, but I have no CloudTrail record of this policy being attached. So AWS can make IAM changes to my account without any audit record. This does not make me feel good.



🗒️ awesome-k8s-security by @magnologan
Great list of resources including:
💊 The Basics
💼 Official Pages
📹 Talks and Videos
📰 Blogs and Articles
📗 Books
📆 Certifications
🔥 CVEs
📑 Slides
🧪 Trainings
🐾 Repositories
📂 Papers
github.com/magnologan/awe…



☁️ Terraformer
Yo dawg, I heard you like Infra *as* Code
But what about Infra to ➡️ Code?
Terraformer generates tf/json and tfstate from your *existing* infra
Supports a number of resources and services at:
* AWS
* GCP
* Azure
* & more! 🚀
github.com/GoogleCloudPla…



Always happy to see more data events in #AWS CloudTrail: This time it's DDB aws.amazon.com/blogs/database…



Haven't a chance to test, but I didn't realise that "Deny" at the Group level don't override "Allow" permissions at other levels (e.g. User) blog.lightspin.io/aws-iam-groups…
Just another reason NOT to use #AWS IAM Users. If you have to, make them assume a role ASAP...



This is big. Literally (some customers do millions of requests per second).

Always happy to see more data events in #AWS CloudTrail: This time it's DDB aws.amazon.com/blogs/database…



Come discuss Infrastructure as code scanning with us on Sunday!

Join us @Owasp_DevSlop on Sunday 28th March: @christophetd will discuss shifting cloud security left and scanning IAC for security issues #cloudsecurity #shiftleft . 🔗: addevent.com/event/rJ6187568



New Console experience... rant.
Dear AWS,
Please stop telling us about the new experience console, when there is so many problems with it. First of all you need to update all your DOCUMENTATION for the new console. Your "howtos" don't match the new console. Secondly, and most important, make sure the new console has …
Can someone put Cloud Security in Newbie terms?
I’m soon to be starting a career in Cloud and want to know more about cloud security. Cybersecurity was my career of choice and I’d love to see how to merge that with my interest in cloud. Can someone explain what cloud security means? How do companies and people secure …
- 🖊️ This newsletter was fwd to you? Subscribe here
- 💌 Want to suggest new content: contact me or reply to this email
- ⚡️ Powered by Mailbrew