Issue #127

Monday · October 23, 2023

🥖 Palate Cleanser

findmytakeover from @malprxctice detects dangling DNS record in a multi cloud environment.

It does this by scanning all the DNS zones and the infrastructure present within the configured cloud service provider either in a single account or multiple accounts and finding the DNS record for which the infrastructure behind it does not exist anymore rather than using wordlist.

It can easily detect and report potential subdomain takeovers that exist.

📋 Chef's selections

  1. IAMActionHunter: Query AWS IAM permission policies with ease
  2. Amazon S3 Inventory can include ACLs as object metadata in inventory reports
  3. Amazon CloudFront announces support for 3072-bit RSA certificates

🍛 Reddit threads on r/aws

🍪 API changes

2023/07/13 - s3 - 5 updated api methods
Changes   S3 Inventory now supports Object Access Control List and Object Owner as available object metadata fields in inventory reports.

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.