Issue #154
Monday · March 11, 2024
๐ Chef's selections
๐ฅ AWS security blogs
๐ Reddit threads on r/aws
- Endless Security Checks
- How do you handle security checks?
- Possible to put a security group on the IGW for global stateful network access rules?
- AWS Config Lambda Custom Rules Remediation
- AWS and IP spoofing
- How to handle customer aws account verification
- Redirect API Gateway to Lambda streaming function URL ?
- EKS Security Best Practices
- Urgent Assistance Needed: AWS Account Compromised with $150K in Unauthorized Charges
- GuardDuty malware scan shortfall
- Need a little bit of help
๐ง IAM permission changes
๐ช API changes
๐น IAM managed policy changes
Managed Policy changed since last week: 5- ๐ฉ AWSMarketplaceResaleAuthorizationServiceRolePolicy
- ๐ฉ AWSMigrationHubOrchestratorServiceRolePolicy
- AWSServiceRoleForCodeWhispererPolicy
- AmazonEKS_CNI_Policy
- ๐ฉ CloudWatchApplicationSignalsServiceRolePolicy
๐ค Powered by MAMIPย | ๐ฉ Sensitive IAM Actions included
โ CloudFormation resource changes
๐ฎ Amazon Linux vulnerabilities
This section will show you the latest (Important and Critical) CVEs on Amazon Linux.Amazon Linux 2
- ALASECS-2024-035 (important): containerdย - CVE-2023-39325, CVE-2023-39326, CVE-2023-3978, CVE-2023-47108