Issue #158

Monday · April 08, 2024

📋 Chef's selections

  1. Terraform module for Certificate Authority on AWS
  2. IAMGraph: Mapping Cross-Account Attack Paths in AWS Environments

🥗 AWS security blogs

🍛 Reddit threads on r/aws

📌

 Stop the money leak (Sponsor)

We are building a 🚚 Garbage collector for your AWS Accounts.

As DevOps engineers building a SaaS product from the ground up for our fellow engineers, we understand the challenges of AWS cost optimization.

We're excited to share our product: unusd.cloud, an automatic waste detection solution designed to reduce your AWS spending, attack surface, and environmental impact 🍃.

With unusd.cloud, you can eliminate wasted spend on unused AWS assets, effortlessly uncover and address active assets you didn't know were still running, and ultimately optimize your AWS budget.

🧁 IAM permission changes

🍪 API changes

🍹 IAM managed policy changes

Managed Policy changed since last week: 17
  1. AWSDeadlineCloud-FleetWorker
  2. AWSDeadlineCloud-UserAccessFarms
  3. AWSDeadlineCloud-UserAccessFleets
  4. AWSDeadlineCloud-UserAccessJobs
  5. AWSDeadlineCloud-UserAccessQueues
  6. AWSDeadlineCloud-WorkerHost
  7. 🚩 AWSDirectoryServiceFullAccess
  8. 🚩 AWSManagedServicesDeploymentToolkitPolicy
  9. AWSMarketplaceGetEntitlements
  10. 🚩 AWSMigrationHubStrategyCollector
  11. AWSServiceRoleForCodeWhispererPolicy
  12. 🚩 AdministratorAccess-Amplify
  13. AmazonDataZoneDomainExecutionRolePolicy
  14. AmazonDataZoneFullUserAccess
  15. 🚩 AmazonDataZoneGlueManageAccessRolePolicy
  16. 🚩 AmazonSageMakerFullAccess
  17. 🚩 AmazonSecurityLakeMetastoreManager
Weekly diff

🤖 Powered by MAMIP | 🚩 Sensitive IAM Actions included

☕ CloudFormation resource changes

  • AWS::Bedrock
  • AWS::SecurityHub
  • AWS::CloudWatch::AnomalyDetector

🎮 Amazon Linux vulnerabilities

This section will show you the latest (Important and Critical) CVEs on Amazon Linux.

No CVE this week 🎉

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.