Issue #159

Monday · April 15, 2024

📋 Chef's selections

  1. CloudFront now supports OAC for Lambda function URL origins
  2. IAM Is The Worst
  3. We discovered an AWS access vulnerability

🥗 AWS security blogs

🍛 Reddit threads on r/aws

🧁 IAM permission changes

🍪 API changes

🍹 IAM managed policy changes

Managed Policy changed since last week: 12
  1. 🚩 AWSIAMIdentityCenterAllowListForIdentityContext
  2. AWSMarketplaceGetEntitlements
  3. 🚩 AWSMigrationHubRefactorSpaces-EnvironmentsWithoutBridgesFullAccess
  4. 🚩 AWSMigrationHubRefactorSpacesFullAccess
  5. AWSSSMForSAPServiceLinkedRolePolicy
  6. AWSXrayFullAccess
  7. 🚩 AmazonRDSCustomServiceRolePolicy
  8. 🚩 AmplifyBackendDeployFullAccess
  9. 🚩 CloudWatchApplicationSignalsServiceRolePolicy
  10. 🚩 ROSAInstallerPolicy
  11. 🚩 ROSASRESupportPolicy
  12. 🚩 SecurityAudit
Weekly diff

🤖 Powered by MAMIP | 🚩 Sensitive IAM Actions included

☕ CloudFormation resource changes

🎮 Amazon Linux vulnerabilities

This section will show you the latest (Important and Critical) CVEs on Amazon Linux.

No CVE this week 🎉

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.