Issue #144

Monday · February 19, 2024

🥖 Palate Cleanser

Hey folks,

As 2023 draws to a close, this marks the final edition of the AWS Security Digest Newsletter for the year.

It's been a fantastic journey sharing the latest and most relevant AWS security updates with you all.

We'll be back in 2024, ready to serve another year of fresh, insightful content in the world of AWS security.

In the meantime, I wish you all a wonderful holiday season. May you enjoy memorable moments with your loved ones during Christmas 🎄.

Cheers!

Victor

📋 Chef's selections

  1. Create and Secure Your First Admin User
  2. Data Exfiltration through S3 Server Access Logs

🥗 AWS security blogs

🍛 Reddit threads on r/aws

🧁 IAM permission changes

🍪 API changes

🍹 IAM managed policy changes

Managed Policy changed since last week: 11
  1. AWSBackupServiceLinkedRolePolicyForBackup
  2. 🚩 AWSBackupServiceRolePolicyForBackup
  3. 🚩 AWSBackupServiceRolePolicyForRestores
  4. AWSElasticDisasterRecoveryNetworkReplicationPolicy
  5. AWSElasticDisasterRecoveryServiceRolePolicy
  6. 🚩 AmazonAthenaFullAccess
  7. 🚩 AmazonDataZoneGlueManageAccessRolePolicy
  8. CostOptimizationHubReadOnlyAccess
  9. IVSFullAccess
  10. 🚩 ROSAImageRegistryOperatorPolicy
  11. 🚩 SecurityAudit
Weekly diff

🤖 Powered by MAMIP | 🚩 Sensitive IAM Actions included

☕ CloudFormation resource changes

🎮 Amazon Linux vulnerabilities

This section will show you the latest (Important and Critical) CVEs on Amazon Linux.

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.