Issue #150

Monday · February 12, 2024

๐Ÿฅ– Palate Cleanser

Hey folks,

This week, I got my first phishing attempt (see below) linked to my aws account. Looks like I'm now on the radar because of my online activities, mainly around AWS work.

I believe it's crucial to alert your operational teams about this, as a breached AWS account can have severe consequences for your business.

Dive into this week's digest of AWS Security news. I've spent hours filtering through AWS updates and announcements so you can kick back and enjoy this quick, 2-minute read.

Also, I shouldn't leave out this update: Amazon GuardDuty Malware Protection has expanded its capabilities to include scanning EBS volumes encrypted with managed keys.

Bon appรฉtit! ๐Ÿฝ๏ธ
Victor

๐Ÿ“‹ Chef's selections

  1. Shift Left Security with Amazon Inspector
  2. Moving away from CDK
  3. Exploring Red Team Persistence via AWS Lex Chatbots

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws

๐Ÿง IAM permission changes

๐Ÿช API changes

๐Ÿน IAM managed policy changes

Managed Policy changed since last week: 15
  1. ๐Ÿšฉ AWSMarketplaceSellerFullAccess
  2. ๐Ÿšฉ AWSMigrationHubStrategyCollector
  3. AWSOrganizationsFullAccess
  4. AWSOrganizationsReadOnlyAccess
  5. AmazonDataZoneDomainExecutionRolePolicy
  6. ๐Ÿšฉ AmazonLexFullAccess
  7. AmazonRedshiftReadOnlyAccess
  8. ๐Ÿšฉ AmazonSageMakerCanvasBedrockAccess
  9. ๐Ÿšฉ AmazonVPCFullAccess
  10. AmazonVPCReadOnlyAccess
  11. ๐Ÿšฉ CloudWatchAgentAdminPolicy
  12. ๐Ÿšฉ CloudWatchAgentServerPolicy
  13. Health_OrganizationsServiceRolePolicy
  14. LakeFormationDataAccessServiceRolePolicy
  15. ๐Ÿšฉ ReadOnlyAccess
Weekly diff

๐Ÿค– Powered by MAMIP
๐Ÿšฉ Sensitive IAM Actions included

โ˜• CloudFormation resource changes

๐ŸŽฎ Amazon Linux vulnerabilities

This section will show you the latest (Important and Critical) CVEs on Amazon Linux.

No CVE this week.

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.