Issue #153
Monday · March 04, 2024
📋 Chef's selections
🥗 AWS security blogs
- New AWS whitepaper: AWS User Guide for Federally Regulated Financial Institutions in Canada
- Enhance container software supply chain visibility through SBOM export with Amazon Inspector and QuickSight
- How to develop an Amazon Security Lake POC
- AWS Payment Cryptography is PCI PIN and P2PE certified
- 2023 H2 IRAP report is now available on AWS Artifact for Australian customers
- AWS recognized as an Overall Leader in 2024 KuppingerCole Leadership Compass for Policy Based Access Management
- Enable multi-admin support to manage security policies at scale with AWS Firewall Manager
- How to use Regional AWS STS endpoints
- Winter 2023 SOC 1 report now available for the first time
- Modern web application authentication and authorization with Amazon VPC Lattice
- AWS HITRUST Shared Responsibility Matrix for HITRUST CSF v11.2 now available
🍛 Reddit threads on r/aws
- Lambda function authentication
- What is the correct approach to limiting a Cognito user to only specific IOT things?
- Suspecting that access tokens were leaked: Where to look for leak?
- Do I need to care about VPC, security groups, WAF, etc.?
- Cloudflare in front of AWS Cognito custom domain?
- AWS Windows Workspaces local administrator account question
- I have a question about EKS SecurityGroup.
- Cannot access Terraform store with new account
- Getting an "Amazon Web Services Sign In With Authentication Device" when accessing Login & Security in Account page on Amazon store
- How to set up MFA using touch ID on Mac or iPhone ?
🧁 IAM permission changes
🍪 API changes
🍹 IAM managed policy changes
Managed Policy changed since last week: 8- 🚩 AWSConfigServiceRolePolicy
- AWSSecurityHubReadOnlyAccess
- 🚩 AWSThinkboxAWSPortalAdminPolicy
- 🚩 AWS_ConfigRole
- 🚩 AmazonRDSCustomInstanceProfileRolePolicy
- 🚩 AmazonSecurityLakeAdministrator
- 🚩 AutoScalingServiceRolePolicy
- 🚩 SecretsManagerReadWrite
🤖 Powered by MAMIP | 🚩 Sensitive IAM Actions included
☕ CloudFormation resource changes
- No update this week.
🎮 Amazon Linux vulnerabilities
This section will show you the latest (Important and Critical) CVEs on Amazon Linux.Amazon Linux 2: