Issue #150
Monday · February 12, 2024
๐ฅ Palate Cleanser
Hey folks,This week, I got my first phishing attempt (see below) linked to my aws account. Looks like I'm now on the radar because of my online activities, mainly around AWS work.
I believe it's crucial to alert your operational teams about this, as a breached AWS account can have severe consequences for your business.
Dive into this week's digest of AWS Security news. I've spent hours filtering through AWS updates and announcements so you can kick back and enjoy this quick, 2-minute read.
Also, I shouldn't leave out this update: Amazon GuardDuty Malware Protection has expanded its capabilities to include scanning EBS volumes encrypted with managed keys.
Bon appรฉtit! ๐ฝ๏ธ
Victor
๐ Chef's selections
๐ฅ AWS security blogs
- How AWS can help you navigate the complexity of digital sovereignty
- AWS completes the 2023 South Korea CSP Safety Assessment Program
- AWS renews K-ISMS certificate for the AWS Asia Pacific (Seoul) Region
- How to migrate asymmetric keys from CloudHSM to AWS KMS
- 2023 C5 Type 2 attestation report available, including two new Regions and 170 services in scope
- How to migrate your on-premises domain to AWS Managed Microsoft AD using ADMT
๐ Reddit threads on r/aws
๐ง IAM permission changes
๐ช API changes
๐น IAM managed policy changes
Managed Policy changed since last week: 15- ๐ฉ AWSMarketplaceSellerFullAccess
- ๐ฉ AWSMigrationHubStrategyCollector
- AWSOrganizationsFullAccess
- AWSOrganizationsReadOnlyAccess
- AmazonDataZoneDomainExecutionRolePolicy
- ๐ฉ AmazonLexFullAccess
- AmazonRedshiftReadOnlyAccess
- ๐ฉ AmazonSageMakerCanvasBedrockAccess
- ๐ฉ AmazonVPCFullAccess
- AmazonVPCReadOnlyAccess
- ๐ฉ CloudWatchAgentAdminPolicy
- ๐ฉ CloudWatchAgentServerPolicy
- Health_OrganizationsServiceRolePolicy
- LakeFormationDataAccessServiceRolePolicy
- ๐ฉ ReadOnlyAccess
๐ค Powered by MAMIP
๐ฉ Sensitive IAM Actions included
โ CloudFormation resource changes
๐ฎ Amazon Linux vulnerabilities
This section will show you the latest (Important and Critical) CVEs on Amazon Linux.No CVE this week.