Issue #147

Monday · January 22, 2024

๐Ÿฅ– Palate Cleanser

Hey folks,

Thanks for your feedback on last week's survey; your input is valuable for planning the year ahead.

Many of you inquired about supporting the newsletter's continuity. The best way to help is by sharing it with your friends and colleagues.

Also, if you're currently reading through the web-view, consider subscribing. It makes a big difference.

Bon appรฉtit! ๐Ÿฝ๏ธ
Victor

๐Ÿ“‹ Chef's selections

  1. Amazon ECS is the new EC2 for crypto mining
  2. The final answer: AWS account IDs are secrets
  3. HTTPS Endpoints and more tricks with AWS Step Functions

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws

Security flair only.

๐Ÿง IAM permission changes

๐Ÿช API changes

  • AWS Transfer Family - 2 updated methods - AWS Transfer Family now supports static IP addresses for SFTP & AS2 connectors and for async MDNs on AS2 servers.
  • AmazonMWAA - 1 updated methods - This Amazon MWAA feature release includes new fields in CreateWebLoginToken response model. The new fields IamIdentity and AirflowIdentity will let you match identifications, as the Airflow identity length is currently hashed to 64 characters.
  • Amazon Keyspaces - 1 new 4 updated methods - This release adds support for Multi-Region Replication with provisioned tables, and Keyspaces auto scaling APIs

๐Ÿน IAM managed policy changes

Managed Policy changed since last week: 6
  1. AWSBillingReadOnlyAccess
  2. AWSElasticDisasterRecoveryCrossAccountReplicationPolicy
  3. AWSElasticDisasterRecoveryServiceRolePolicy
  4. ๐Ÿšฉ AWSSupportServiceRolePolicy
  5. AWSTrustedAdvisorServiceRolePolicy
  6. Billing
Weekly diff

๐Ÿค– Powered by MAMIP | ๐Ÿšฉ Sensitive IAM Actions included

โ˜• CloudFormation resource changes

๐ŸŽฎ Amazon Linux vulnerabilities

This section will show you the latest (Important and Critical) CVEs on Amazon Linux.
Amazon Linux 2

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.