Security Newsletter - 533 million Facebook users' data leaked. PHP backdoor attempt. Github Actions used for coinmining. Minimal issue. • SRE Weekly Issue #264 • 📖 [The CloudSecList] Issue 81 • [tl;dr sec] #77 - Hidden OAuth attack vectors, Networking Fundamentals • AWS WAF now supports Labels to improve rule customization and reporting • AWS Firewall Manager now supports centralized deployment of the new AWS WAF Bot Control across your organization • AWS Firewall Manager now supports centralized management of Amazon Route 53 Resolver DNS Firewall • Announcing AWS WAF Bot Control for visibility and control over common and pervasive bots • 7 ways to improve security of your machine learning workflows • Whistleblower: Ubiquiti Breach “Catastrophic” – Krebs on Security • Troubleshoot Boot and Networking Issues with New EC2 Serial Console | Amazon Web Services • Hack Alongside Hackers | HackerOne • 😂😂 • 📈 Networking Fundamentals: From Zero to HTTP Great intro and overview by <a href="https://twitter.com/TomNomNom" target="_blank">@TomNomNom</a>, covering topics like: * MAC addresses * ARP * Hubs, switches * Subnets, CIDR * Routing, TCP/IP, DNS * Load balancers, NAT, etc. 📖 <a href="https://t.co/rs1Bk2bajJ" target="_blank">tomnomnom.com/talks/networki…</a> 📺 <a href="https://t.co/f9E2QOUSBa" target="_blank">youtube.com/watch?v=9uebak…</a> • I'm hiring! <a href="https://t.co/1Ai8dlsQDH" target="_blank">aurora.tech/jobs/senior-cl…</a> • This is big! Using this will mitigate a common exfil path when people attempt to setup isolated networks on AWS or otherwise attempt to restrict network egress. I described the DNS exfil trick here: <a href="https://t.co/RQJS4Ccarc" target="_blank">summitroute.com/blog/2020/03/3…</a> • 📚 tl;dr sec 77 * <a href="https://twitter.com/artsploit" target="_blank">@artsploit</a> New OAuth attacks * <a href="https://twitter.com/TomNomNom" target="_blank">@TomNomNom</a> Networking fundamentals * <a href="https://twitter.com/mikepsecuritee" target="_blank">@mikepsecuritee</a> Career advice * <a href="https://twitter.com/trailofbits" target="_blank">@trailofbits</a> Audit of NYT's SecureDrop Workstation * <a href="https://twitter.com/DanielMiessler" target="_blank">@DanielMiessler</a> Consumer Authn Strength Maturity Model <a href="https://t.co/0IT3KZnOQp" target="_blank">tldrsec.com/blog/tldr-sec-…</a> • Just blogged: "Kubernetes Lab on Baremetal" - My personal approach to deploy my own <a href="https://twitter.com/hashtag/Kubernetes" target="_blank">#Kubernetes</a> Lab on baremetal, and on an Intel NUC in particular. <a href="https://t.co/uvloqWCDKY" target="_blank">marcolancini.it/2021/blog-kube…</a> • "Getting access to an instance’s console is a privileged operation that should be tightly controlled, which is why EC2 Serial Console access is not permitted by default at the account level..." AWS is learning (how to keep new things disabled by default)! <a href="https://t.co/RAqFNIpdLN" target="_blank">aws.amazon.com/blogs/aws/trou…</a> • It's good to know that this IAM policy is just as confused as I am. • In case anyone is rolling out AWS Service Control Policies (SCPs) for proactive security guardrails: you gotta have a way to make exceptions. Otherwise you’ll break things. Try using these condition keys to make exceptions.👇 you’ll roll SCPs out faster • Helpful recap of AWS Organizations features that have come out in the last ~quarter: <a href="https://t.co/LASoUPb540" target="_blank">aws.amazon.com/blogs/mt/the-l…</a> <a href="https://twitter.com/AWSIdentity" target="_blank">@AWSIdentity</a> • AWS Lambda@Edge changes duration billing granularity from 50ms down to 1ms • Troubleshoot Boot and Networking Issues with New EC2 Serial Console • One Year of Graviton2 at Honeycomb: A Retrospective • CloudWatch Metric Streams – Send AWS Metrics to Partners and to Your Apps in Real Time | Amazon Web Services • AWS launches new EFS storage class that cuts costs in half • Cheating the cheater: How adversaries are using backdoored video game cheat engines and modding tools • Bloodhound for Linux • Practice Cloud Security • Innovative Solutions Launches Cutting Edge Managed Service Offerings for Amazon Web Services Customers - PRNewswire • Verizon Business Brings Private Mobile Edge Compute to Enterprise Customers with AWS - StreetInsider.com • Privacera Provides Enterprise-ready Data Access Governance and Security with New AWS EMR Record Server Integration - PRNewswire
5
Monday April, 2021

AWS WAF now supports Labels to improve rule customization and reporting

AWS WAF now lets you generate labels and customize your WAF rules based on those labels. With this feature, you can configure WAF to add descriptive labels to web requests when a WAF rule matches the request, regardless of the action associated with the rule. You can also check for …

AWS Firewall Manager now supports centralized deployment of the new AWS WAF Bot Control across your organization

AWS Firewall Manager now enables security administrators to deploy the recently launched AWS WAF Bot Control across accounts in their organization, from a central administrator account. AWS WAF Bot Control is a new managed rule group that gives you visibility and control over common and pervasive bot traffic to your …

AWS Firewall Manager now supports centralized management of Amazon Route 53 Resolver DNS Firewall

AWS Firewall Manager now supports Amazon Route 53 Resolver DNS Firewall, making it easy for security administrators to identify the set of DNS Firewall rules they wish to use and deploy across their organization, from a central place. AWS recently launched Amazon Route 53 Resolver DNS Firewall, a managed firewall …

Announcing AWS WAF Bot Control for visibility and control over common and pervasive bots

AWS WAF announces the launch of AWS WAF Bot Control, which gives you visibility and control over common and pervasive bots that consume excess resources, skew metrics, cause downtime, or perform other undesired activities. With Bot Control, you can easily monitor, block, or rate-limit pervasive bots, such as scrapers, scanners, …

7 ways to improve security of your machine learning workflows

Annalyn NgMar 31
In this post, you will learn how to use familiar security controls to build more secure machine learning (ML) workflows. The ideal audience for this post includes data scientists who want to learn basic ways to improve security of their ML workflows, as well as security engineers who want to …
clintgibler
Clint Gibler @clintgibler

📈 Networking Fundamentals: From Zero to HTTP

Great intro and overview by @TomNomNom, covering topics like:

* MAC addresses
* ARP
* Hubs, switches
* Subnets, CIDR
* Routing, TCP/IP, DNS
* Load balancers, NAT, etc.

📖 tomnomnom.com/talks/networki…
📺 youtube.com/watch?v=9uebak…

41Mar 30 · 5:00 PM
0xdabbad00
Scott Piper @0xdabbad00

This is big! Using this will mitigate a common exfil path when people attempt to setup isolated networks on AWS or otherwise attempt to restrict network egress.

I described the DNS exfil trick here: summitroute.com/blog/2020/03/3…

17Apr 01 · 5:23 AM
clintgibler
Clint Gibler @clintgibler

📚 tl;dr sec 77
* @artsploit New OAuth attacks
* @TomNomNom Networking fundamentals
* @mikepsecuritee Career advice
* @trailofbits Audit of NYT's SecureDrop Workstation
* @DanielMiessler Consumer Authn Strength Maturity Model

tldrsec.com/blog/tldr-sec-…

18Apr 01 · 5:00 PM
lancinimarco
Marco Lancini @lancinimarco

Just blogged: "Kubernetes Lab on Baremetal" - My personal approach to deploy my own #Kubernetes Lab on baremetal, and on an Intel NUC in particular. marcolancini.it/2021/blog-kube…

11Mar 30 · 12:11 PM
matthewdfuller
Matt Fuller @matthewdfuller

"Getting access to an instance’s console is a privileged operation that should be tightly controlled, which is why EC2 Serial Console access is not permitted by default at the account level..."

AWS is learning (how to keep new things disabled by default)!
aws.amazon.com/blogs/aws/trou…

5Mar 31 · 12:32 AM
__steele
Aidan W Steele @__steele

It's good to know that this IAM policy is just as confused as I am.

1Mar 30 · 2:42 AM
kmcquade3
Kinnaird McQuade💥☁️ @kmcquade3

In case anyone is rolling out AWS Service Control Policies (SCPs) for proactive security guardrails: you gotta have a way to make exceptions. Otherwise you’ll break things.

Try using these condition keys to make exceptions.👇 you’ll roll SCPs out faster

kmcquade3
Kinnaird McQuade💥☁️ @kmcquade3

@ben11kehoe @mchancloud 😊 The best ways to make exceptions in AWS SCPs are via these global condition keys:
- aws:PrincipalAccount (account level exceptions)
- aws:PrincipalOrgPaths (environment/OU level exceptions)
- aws:PrincipalArn (user/role level exceptions, but kinda limited b/c no * support)

5Apr 01 · 3:01 AM
jim_scharf
Jim Scharf @jim_scharf

Helpful recap of AWS Organizations features that have come out in the last ~quarter: aws.amazon.com/blogs/mt/the-l… @AWSIdentity

8Mar 30 · 4:36 PM

Practice Cloud Security

Hello folks,

As I continue the journey of learning Cloud Security, I found myself wanting to put what I’ve learned to practice but I’m not sure where to go from here.

Is there a platform (paid or free) that allows you to practice cloud security concepts? For example, if I …