Issue #145

Monday · February 26, 2024

๐Ÿฅ– Palate Cleanser

Hey folks,

Happy New Year! ๐Ÿพ Ready to cook up some cloud security masterpieces in 2024?

Let's start this year with a flavor-packed menu of insights and updates.

As your head chef in the AWS Security kitchen, I'm always looking to spice things up. Your appetite for knowledge and your feedback are the secret ingredients that make our community sizzle.

Now, for the main course in this issue: I've whipped up a special HTTPS redirect recipe. It's like transforming a simple sub.domainA.tld into a gourmet other.domainB.tld, seasoned with CloudFront Function and the fresh-out-of-the-oven CloudFront KeyValueStore.

So, tie your apron, sharpen your skills, and let's get ready to feast on the cloud's delicious offerings in 2024!

Here's to a year of succulent solutions and cloud culinary adventures! ๐Ÿณ

Bon Appรฉtit!
Victor

๐Ÿ“‹ Chef's selections

  1. Setting secure defaults on AWS and avoiding misconfigurations
  2. AWS Account Security Onboarding Mind Map
  3. CDK Goat - Vulnerable AWS CDK Infrastructure

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws

๐Ÿง IAM permission changes

๐Ÿช API changes

๐Ÿน IAM managed policy changes

Managed Policy changed since last week: 10
  1. AWSApplicationMigrationServiceEc2InstancePolicy
  2. AWSArtifactReportsReadOnlyAccess
  3. AWSElasticDisasterRecoveryNetworkReplicationPolicy
  4. AWSElasticDisasterRecoveryServiceRolePolicy
  5. ๐Ÿšฉ AWSServiceRoleForAmazonEKSNodegroup
  6. ๐Ÿšฉ AmazonAthenaFullAccess
  7. ๐Ÿšฉ AmplifyBackendDeployFullAccess
  8. CloudFrontFullAccess
  9. CloudFrontReadOnlyAccess
  10. ๐Ÿšฉ ReadOnlyAccess
Weekly diff

๐Ÿค– Powered by MAMIPย | ๐Ÿšฉ Sensitive IAM Actions included

โ˜• CloudFormation resource changes

๐ŸŽฎ Amazon Linux vulnerabilities

This section will show you the latest (Important and Critical) CVEs on Amazon Linux.

    No CVE since last issue.

    Get every AWS security change,
    on a plate every Monday.

    6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.