Issue #142

Monday · February 05, 2024

๐Ÿฅ– Palate Cleanser

Hey folks,

I have to admit, I'm somewhat underwhelmed by the announcements at re:Invent 2023. It seems like there weren't any groundbreaking features or exciting developments this time around. Perhaps I've been in the industry too long and have become a bit jaded?

The highlights for me were the introduction of S3 Express OZ, the new AWS AI-powered TAM (Amazon Q, wait, Q like in James Bond? ๐Ÿคต), and S3 Access Grants methods (yet another way to fail on security).

Hope you've recovered from your post re:Invent blues. Stay well, everyone.

What about you? What did you think of this year's event? Feel free to hit reply and share your thoughts.

Victor

๐Ÿ“‹ Chef's selections

  1. Scaling data access with Amazon S3 Access Grants
  2. Announcing major dashboard enhancements in AWS Security Hub
  3. AWS Activity Summary and Visualization Tool

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws

๐Ÿง IAM permission changes

๐Ÿช API changes

๐Ÿน IAM managed policy changes

Managed Policy changed since last week: 48 (Large one due to re:Invent ๐Ÿคข)
  1. ๐Ÿšฉ AWSBackupFullAccess
  2. AWSBackupServiceLinkedRolePolicyForBackup
  3. ๐Ÿšฉ AWSBackupServiceRolePolicyForBackup
  4. ๐Ÿšฉ AWSBackupServiceRolePolicyForRestores
  5. ๐Ÿšฉ AWSCleanRoomsMLFullAccess
  6. AWSCleanRoomsMLReadOnlyAccess
  7. AWSElasticDisasterRecoveryAgentInstallationPolicy
  8. AWSElasticDisasterRecoveryAgentPolicy
  9. ๐Ÿšฉ AWSElasticDisasterRecoveryConsoleFullAccess_v2
  10. AWSElasticDisasterRecoveryConversionServerPolicy
  11. ๐Ÿšฉ AWSElasticDisasterRecoveryEc2InstancePolicy
  12. AWSElasticDisasterRecoveryFailbackInstallationPolicy
  13. AWSElasticDisasterRecoveryFailbackPolicy
  14. AWSElasticDisasterRecoveryNetworkReplicationPolicy
  15. ๐Ÿšฉ AWSElasticDisasterRecoveryReadOnlyAccess
  16. ๐Ÿšฉ AWSElasticDisasterRecoveryRecoveryInstancePolicy
  17. AWSElasticDisasterRecoveryReplicationServerPolicy
  18. AWSElasticDisasterRecoveryServiceRolePolicy
  19. ๐Ÿšฉ AWSElasticDisasterRecoveryStagingAccountPolicy
  20. ๐Ÿšฉ AWSElasticDisasterRecoveryStagingAccountPolicy_v2
  21. ๐Ÿšฉ AWSFaultInjectionSimulatorEC2Access
  22. AWSFinSpaceServiceRolePolicy
  23. AWSSecurityHubServiceRolePolicy
  24. AWSServiceRoleForNeptuneGraphPolicy
  25. AWSZonalAutoshiftPracticeRunSLRPolicy
  26. AccessAnalyzerServiceRolePolicy
  27. ๐Ÿšฉ AmazonConnectServiceLinkedRolePolicy
  28. AmazonDataZoneDomainExecutionRolePolicy
  29. AmazonDataZoneFullUserAccess
  30. AmazonDetectiveInvestigatorAccess
  31. AmazonEKSWorkerNodePolicy
  32. AmazonElastiCacheFullAccess
  33. ๐Ÿšฉ AmazonElasticFileSystemFullAccess
  34. AmazonFSxConsoleFullAccess
  35. AmazonFSxFullAccess
  36. AmazonOneEnterpriseFullAccess
  37. AmazonOneEnterpriseInstallerAccess
  38. AmazonOneEnterpriseReadOnlyAccess
  39. AmazonQFullAccess
  40. ๐Ÿšฉ AmazonSageMakerCanvasAIServicesAccess
  41. ๐Ÿšฉ AmazonSageMakerClusterInstanceRolePolicy
  42. ๐Ÿšฉ AmazonSageMakerFullAccess
  43. CloudTrailServiceRolePolicy
  44. ElastiCacheServiceRolePolicy
  45. IAMAccessAnalyzerReadOnlyAccess
  46. ๐Ÿšฉ NeptuneConsoleFullAccess
  47. ๐Ÿšฉ NeptuneGraphReadOnlyAccess
  48. ๐Ÿšฉ ReadOnlyAccess
Weekly diff
๐Ÿค– Powered by MAMIPย | ๐Ÿšฉ Sensitive IAM Actions included

โ˜• CloudFormation resource changes

  • AWS::S3Express::DirectoryBucket /ย AWS::S3Express::BucketPolicy
  • AWS::ElastiCache::ServerlessCache
  • AWS::AccessAnalyzer::Analyzer
  • AWS::Backup::RestoreTestingPlan /ย AWS::Backup::RestoreTestingSelection
  • AWS::ManagedBlockchain::Accessor
  • AWS::EKS::PodIdentityAssociation

๐ŸŽฎ Amazon Linux vulnerabilities

This section will show you the latest (Important and Critical) CVEs on Amazon Linux.
  • No CVEs published this week on Amazon Linux OS.

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.