Issue #158
Monday · April 08, 2024
📋 Chef's selections
🥗 AWS security blogs
🍛 Reddit threads on r/aws
- Are there risks I'm overlooking with a public EKS endpoint?
- Need help setting up a ECS Task with awsvpc mode
- Clotho: A library and egress proxy that acts as a CASB
- Protect my AWS ECS service node.js backend
- Most cost effective way to secure a static site hosted on S3 through Cloudfront distribution?
- Private key of a .pem file should be the only way to SSH into EC2.
📌
Stop the money leak (Sponsor)We are building a 🚚 Garbage collector for your AWS Accounts.
As DevOps engineers building a SaaS product from the ground up for our fellow engineers, we understand the challenges of AWS cost optimization.
We're excited to share our product: unusd.cloud, an automatic waste detection solution designed to reduce your AWS spending, attack surface, and environmental impact 🍃.
With unusd.cloud, you can eliminate wasted spend on unused AWS assets, effortlessly uncover and address active assets you didn't know were still running, and ultimately optimize your AWS budget.
🧁 IAM permission changes
🍪 API changes
🍹 IAM managed policy changes
Managed Policy changed since last week: 17- AWSDeadlineCloud-FleetWorker
- AWSDeadlineCloud-UserAccessFarms
- AWSDeadlineCloud-UserAccessFleets
- AWSDeadlineCloud-UserAccessJobs
- AWSDeadlineCloud-UserAccessQueues
- AWSDeadlineCloud-WorkerHost
- 🚩 AWSDirectoryServiceFullAccess
- 🚩 AWSManagedServicesDeploymentToolkitPolicy
- AWSMarketplaceGetEntitlements
- 🚩 AWSMigrationHubStrategyCollector
- AWSServiceRoleForCodeWhispererPolicy
- 🚩 AdministratorAccess-Amplify
- AmazonDataZoneDomainExecutionRolePolicy
- AmazonDataZoneFullUserAccess
- 🚩 AmazonDataZoneGlueManageAccessRolePolicy
- 🚩 AmazonSageMakerFullAccess
- 🚩 AmazonSecurityLakeMetastoreManager
🤖 Powered by MAMIP | 🚩 Sensitive IAM Actions included
☕ CloudFormation resource changes
- AWS::Bedrock
- AWS::SecurityHub
- AWS::CloudWatch::AnomalyDetector
🎮 Amazon Linux vulnerabilities
This section will show you the latest (Important and Critical) CVEs on Amazon Linux.No CVE this week 🎉