Issue #139

Monday · January 15, 2024

🥖 Palate Cleanser

Hey folks,

AWS is still shipping some new significant features, and there is no (yet) freeze before re:Invent 2023 (in 14 days).

Interestingly, following the announcement of Block Public Sharing for AMI a few weeks ago, AWS introduced the same capacity but for Snapshots.

I've updated my AWS Security Survival Kit (Open Source) with this new capacity to let you apply bare minimal AWS security to your accounts. (Alerting and Configuration)

Victor

📋 Chef's selections

  1. Amazon EC2 Instance Metadata Service IMDSv2 by default
  2. Block Public Sharing of Amazon EBS Snapshots
  3. Amazon GuardDuty introduces new machine learning capability

🍛 Reddit threads on r/aws

🍪 API changes

🍹 IAM managed policy changes

Managed Policy changed since last week: 16
  1. 🚩 AWSAuditManagerServiceRolePolicy
  2. 🚩 AWSIAMIdentityCenterAllowListForIdentityContext
  3. AWSIPAMServiceRolePolicy
  4. AWSIncidentManagerIncidentAccessServiceRolePolicy
  5. AWSKeyManagementServiceCustomKeyStoresServiceRolePolicy
  6. AWSResourceExplorerServiceRolePolicy
  7. AWSSecurityHubServiceRolePolicy
  8. AWSServiceCatalogAppRegistryFullAccess
  9. AWSServiceRolePolicyForBackupRestoreTesting
  10. AWSTrustedAdvisorServiceRolePolicy
  11. AccessAnalyzerServiceRolePolicy
  12. AmazonConnectCampaignsServiceLinkedRolePolicy
  13. AmazonRekognitionReadOnlyAccess
  14. 🚩 AmplifyBackendDeployFullAccess
  15. 🚩 CloudWatchApplicationSignalsServiceRolePolicy
  16. 🚩 PartnerCentralAccountManagementUserRoleAssociation
Weekly diff

🤖 Powered by MAMIP - 🚩 Sensitive IAM Actions included

☕ CloudFormation resource changes

🎮 Amazon Linux vulnerabilities

This section will show you the latest (Important and Critical) CVEs on Amazon Linux.
  • Nothing to see here this week.

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.