Issue #140

Monday · January 22, 2024

🥖 Palate Cleanser

Hey folks,

Big shoutout to our latest sponsor, Wiz, for their support with this newsletter – couldn't have done it without them!

This issue features an insightful report from Datadog's research team on Cloud Security's current landscape, offering a valuable perspective by comparing it to previous studies. It's a must-read for grasping corporate trends.

Plus, we've got updates on over 29 IAM Managed Policies.

Victor

📋 Chef's selections

  1. Reversing AWS IAM unique IDs
  2. Datadog's State of Cloud Security
  3. Use scalable controls for AWS services accessing your resources

🥗 AWS security blogs

🍛 Reddit threads on r/aws

🧁 IAM permission changes

🍪 API changes

  • TrustedAdvisor Public API - 10 new methods - AWS Trusted Advisor introduces new APIs to enable you to programmatically access Trusted Advisor best practice checks, recommendations, and prioritized recommendations. Trusted Advisor APIs enable you to integrate Trusted Advisor with your operational tools to automate your workloads.
  • AWS Lambda - 8 updated methods - Adds support for logging configuration in Lambda Functions. Customers will have more control how their function logs are captured and to which cloud watch log group they are delivered also.
  • Amazon Elastic Compute Cloud - 3 new 24 updated methods - AWS EBS now supports Snapshot Lock, giving users the ability to lock an EBS Snapshot to prohibit deletion of the snapshot. This release introduces the LockSnapshot, UnlockSnapshot & DescribeLockedSnapshots APIs to manage lock configuration for snapshots. The release also includes the dl2q_24xlarge.

🍹 IAM managed policy changes

Managed Policy changed since last week: 29
  1. AWSApplicationAutoscalingSageMakerEndpointPolicy
  2. 🚩 AWSConfigServiceRolePolicy
  3. 🚩 AWSDataLifecycleManagerSSMFullAccess
  4. 🚩 AWSECRPullThroughCache_ServiceRolePolicy
  5. 🚩 AWSFaultInjectionSimulatorEC2Access
  6. AWSFaultInjectionSimulatorEKSAccess
  7. AWSFaultInjectionSimulatorRDSAccess
  8. AWSGitSyncServiceRolePolicy
  9. AWSIncidentManagerIncidentAccessServiceRolePolicy
  10. AWSIoTTwinMakerServiceRolePolicy
  11. AWSMarketplaceDeploymentServiceRolePolicy
  12. 🚩 AWSRefactoringToolkitFullAccess
  13. 🚩 AWSResourceExplorerFullAccess
  14. 🚩 AWSResourceExplorerOrganizationsAccess
  15. AWSResourceExplorerReadOnlyAccess
  16. AWSSSMForSAPServiceLinkedRolePolicy
  17. AWSSecurityHubFullAccess
  18. AWSSecurityHubOrganizationsAccess
  19. AWSServiceRoleForIoTSiteWise
  20. AWSVPCVerifiedAccessServiceRolePolicy
  21. 🚩 AWS_ConfigRole
  22. AWSrePostPrivateCloudWatchAccess
  23. 🚩 AmazonConnectServiceLinkedRolePolicy
  24. 🚩 AmazonDataZoneEnvironmentRolePermissionsBoundary
  25. AmazonDataZoneRedshiftManageAccessRolePolicy
  26. AmazonGuardDutyFullAccess
  27. AmazonGuardDutyReadOnlyAccess
  28. 🚩 AmplifyBackendDeployFullAccess
  29. EC2ImageBuilderLifecycleExecutionPolicy
Weekly diff

🤖 Powered by MAMIP - 🚩 Sensitive IAM Actions included

☕ CloudFormation resource changes

🎮 Amazon Linux vulnerabilities

This section will show you the latest (Important and Critical) CVEs on Amazon Linux.
  • No CVEs published this week on Amazon Linux OS.

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.