Issue #143

Monday · February 12, 2024

🥖 Palate Cleanser

Hey folks,

This week, I've launched two new open-source projects.

The first one facilitates hosting static websites internally on AWS without the need for CloudFront.

The second project serves as a tool to assist with the Default Host Management Settings for AWS SSM at the AWS Account Level.

Additionally, we're excited to announce sponsorship openings for the AWS Security Digest for 2024. If you're interested in supporting our newsletter and helping us continue into 2024, please reach out. This is an excellent chance to showcase your product and expertise in the field.

Cheers!

Victor

📋 Chef's selections

  1. IMDSPOOF is a cyber deception tool that spoofs an AWS IMDS service
  2. How fast is CloudTrail today? Investigating CloudTrail delays using Athena
  3. By the same token: How adversaries infiltrate AWS cloud accounts

🥗 AWS security blogs

🍛 Reddit threads on r/aws

🧁 IAM permission changes

🍪 API changes

🍹 IAM managed policy changes

Managed Policy changed since last week: 19
  1. 🚩 AWSAuditManagerServiceRolePolicy
  2. AWSBatchServiceRole
  3. 🚩 AWSConfigServiceRolePolicy
  4. AWSMSKReplicatorExecutionRole
  5. 🚩 AWSMigrationHubOrchestratorConsoleFullAccess
  6. AWSServiceCatalogAppRegistryFullAccess
  7. 🚩 AWSSupportServiceRolePolicy
  8. 🚩 AWS_ConfigRole
  9. 🚩 AmazonBedrockFullAccess
  10. AmazonBedrockReadOnly
  11. 🚩 AmazonChimeSDKMediaPipelinesServiceLinkedRolePolicy
  12. 🚩 AmazonECSServiceRolePolicy
  13. 🚩 AmazonSageMakerCanvasDataPrepFullAccess
  14. 🚩 AmazonSageMakerCanvasFullAccess
  15. BatchServiceRolePolicy
  16. 🚩 CloudWatchFullAccessV2
  17. CloudWatchReadOnlyAccess
  18. IVSReadOnlyAccess
  19. 🚩 ReadOnlyAccess
Weekly diff

🤖 Powered by MAMIP | 🚩 Sensitive IAM Actions included

☕ CloudFormation resource changes

🎮 Amazon Linux vulnerabilities

This section will show you the latest (Important and Critical) CVEs on Amazon Linux.
  • No CVEs published this week on Amazon Linux OS.

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.