Issue #152

Monday · February 26, 2024

๐Ÿฅ– Palate Cleanser

Hey folks,

This week, I really appreciate the return of the famous blog post about detecting manual change made in AWS Console, updated with a 2024 version. A must read.

Also, a new technique, to find any AWS Accountid from an S3 bucket name (public or private).

You will find the associated code in this repository.

Bon appetit!
Victor

๐Ÿ“‹ Chef's selections

  1. When AWS invariants aren't [invariant]
  2. Detecting Manual AWS Actions: An Update!
  3. How to secure CI/CD roles without burning production to theย ground

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws

๐Ÿง IAM permission changes

๐Ÿช API changes

๐Ÿน IAM managed policy changes

Managed Policy changed since last week: 11
  1. ๐Ÿšฉ AWSConfigServiceRolePolicy
  2. ๐Ÿšฉ AWSDataSyncFullAccess
  3. AWSIncidentManagerIncidentAccessServiceRolePolicy
  4. AWSSecurityHubReadOnlyAccess
  5. ๐Ÿšฉ AWS_ConfigRole
  6. AmazonRedshiftQueryEditorV2FullAccess
  7. AmazonRedshiftQueryEditorV2NoSharing
  8. AmazonRedshiftQueryEditorV2ReadSharing
  9. AmazonRedshiftQueryEditorV2ReadWriteSharing
  10. IVSReadOnlyAccess
  11. ๐Ÿšฉ SecretsManagerReadWrite
Weekly diff

๐Ÿค– Powered by MAMIPย | ๐Ÿšฉ Sensitive IAM Actions included

โ˜• CloudFormation resource changes

๐ŸŽฎ Amazon Linux vulnerabilities

This section will show you the latest (Important and Critical) CVEs on Amazon Linux.

No CVE this weekย ๐ŸŽ‰

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.