Issue #155
Monday · March 18, 2024
📋 Chef's selections
🥗 AWS security blogs
🍛 Reddit threads on r/aws
- Password breaks secret manager
- ECS Fargate with FIPS enabled issues
- AWS Control Tower in an existing Organization
- Encrypted search question
- if i use protocol buffers that inter exchange client and server is "aws managed waf" aware on how to detect i.e sql injections or xss or any of the common ones? or should i stick to json and not binary format
- Rant: AWS Cognitio forcing you to pay for advanced security for important feature
🧁 IAM permission changes
🍪 API changes
🍹 IAM managed policy changes
Managed Policy changed since last week: 9- 🚩 AWSCodePipeline_FullAccess
- 🚩 AWSMarketplaceSellerFullAccess
- AmazonDataZoneDomainExecutionRolePolicy
- 🚩 AmazonDataZoneFullAccess
- AmazonDataZoneFullUserAccess
- 🚩 AmazonDataZoneRedshiftGlueProvisioningPolicy
- 🚩 AmazonLexReplicationPolicy
- AmazonTimestreamInfluxDBFullAccess
- 🚩 AmazonTimestreamInfluxDBServiceRolePolicy
🤖 Powered by MAMIP | 🚩 Sensitive IAM Actions included
☕ CloudFormation resource changes
🎮 Amazon Linux vulnerabilities
This section will show you the latest (Important and Critical) CVEs on Amazon Linux.No CVE this week 🎉