Issue #146

Monday · January 15, 2024

🥖 Palate Cleanser

Hey folks,

This year, I've got a small favor to ask you. Your thoughts and feedback on our newsletter are like secret ingredients to us. They help us whip up the perfect blend of content - fresh, secure, and exactly to your taste.

So, could you spare a moment to tell us what you love, what you'd toss out, and any flavor you think we're missing? Your input is crucial in helping us serve up the most satisfying AWS security feast.

Here's a quick survey to share your thoughts.

Thank you for helping us make this newsletter better for everyone!

Bon appétit! 🍽️
Victor

📋 Chef's selections

  1. Research Uncovers AWS Account Numbers Hidden in Access Keys
  2. AWS CloudShell analysis: privileged container, exposed block devices and container escape(s)
  3. Amazon CloudWatch Logs now supports account level

🥗 AWS security blogs

🍛 Reddit threads on r/aws

Security flair only.

🧁 IAM permission changes

🍪 API changes

🍹 IAM managed policy changes

Managed Policy changed since last week: 9
  1. 🚩 AWSGrafanaWorkspacePermissionManagementV2
  2. AWSLambdaVPCAccessExecutionRole
  3. AccessAnalyzerServiceRolePolicy
  4. AmazonECSInfrastructureRolePolicyForVolumes
  5. AmazonFSxConsoleFullAccess
  6. AmazonFSxConsoleReadOnlyAccess
  7. AmazonFSxFullAccess
  8. 🚩 AmazonFSxServiceRolePolicy
  9. 🚩 DynamoDBReplicationServiceRolePolicy
Weekly diff
🤖 Powered by MAMIP - 🚩 Sensitive IAM Actions included

☕ CloudFormation resource changes

🎮 Amazon Linux vulnerabilities

This section will show you the latest (Important and Critical) CVEs on Amazon Linux.
Amazon Linux 2

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.