Issue #153

Monday · March 04, 2024

📋 Chef's selections

  1. Hacking Terraform State for Privilege Escalation
  2. Auditing AWS EKS Pod Permissions
  3. The state of ABAC on AWS (in 2024)

🥗 AWS security blogs

🍛 Reddit threads on r/aws

🧁 IAM permission changes

🍪 API changes

🍹 IAM managed policy changes

Managed Policy changed since last week: 8
  1. 🚩 AWSConfigServiceRolePolicy
  2. AWSSecurityHubReadOnlyAccess
  3. 🚩 AWSThinkboxAWSPortalAdminPolicy
  4. 🚩 AWS_ConfigRole
  5. 🚩 AmazonRDSCustomInstanceProfileRolePolicy
  6. 🚩 AmazonSecurityLakeAdministrator
  7. 🚩 AutoScalingServiceRolePolicy
  8. 🚩 SecretsManagerReadWrite
Weekly diff

🤖 Powered by MAMIP | 🚩 Sensitive IAM Actions included

☕ CloudFormation resource changes

  • No update this week.

🎮 Amazon Linux vulnerabilities

This section will show you the latest (Important and Critical) CVEs on Amazon Linux.

Amazon Linux 2:

ALAS-2024-2473 (important): sudo

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.