Issue #159
Monday · April 15, 2024
📋 Chef's selections
🥗 AWS security blogs
🍛 Reddit threads on r/aws
- Prevent brute force RDP attacks on EC2
- Revoking token in cognito
- Securing AWS Cognito Signup Route
- Database tier still working after remove outgoing traffic in security group
- SecOps Solution For Our AWS CodePipelines
- Financial Risks of hosting an ELB with a domain
- if I install AWS security tools, do I need to install it for every account?
- Cyber Security swap from Azure to AWS
- Question about IAM Roles Anywhere
- Security Monitoring in AWS: Cloudtrail, Cloudwatch and Eventbridge
- Restricting Administrator user in management account from certain actions
- PassRole Permissions - Using Responsibly?
- Use AWS Gateway API Keys as website password
🧁 IAM permission changes
🍪 API changes
🍹 IAM managed policy changes
Managed Policy changed since last week: 12- 🚩 AWSIAMIdentityCenterAllowListForIdentityContext
- AWSMarketplaceGetEntitlements
- 🚩 AWSMigrationHubRefactorSpaces-EnvironmentsWithoutBridgesFullAccess
- 🚩 AWSMigrationHubRefactorSpacesFullAccess
- AWSSSMForSAPServiceLinkedRolePolicy
- AWSXrayFullAccess
- 🚩 AmazonRDSCustomServiceRolePolicy
- 🚩 AmplifyBackendDeployFullAccess
- 🚩 CloudWatchApplicationSignalsServiceRolePolicy
- 🚩 ROSAInstallerPolicy
- 🚩 ROSASRESupportPolicy
- 🚩 SecurityAudit
🤖 Powered by MAMIP | 🚩 Sensitive IAM Actions included
☕ CloudFormation resource changes
🎮 Amazon Linux vulnerabilities
This section will show you the latest (Important and Critical) CVEs on Amazon Linux.No CVE this week 🎉