Issue #161

Monday · June 10, 2024

📋 Chef's selections

  1. AWS CloudQuarry: Digging for Secrets in Public AMIs

    What happens if you download 3.1 million public AMIs across 27 AWS regions and scan them for juicy secrets? Firstly, you probably burn a lot of time and money because that’s a lot storage and compute. In just under 10,000 compelling words Matei Josephs and Eduard Agavriloae explain how they did the work and what they found. If you are attracted to internet-scale scanning projects, this one is for you. Make sure to have a soft toy to cuddle. This one is scary.

  2. The Universal Cloud Threat Model

    A good threat model can help you quickly identify problem areas in a security model. A bad one can give you a false sense of security and make you want to watch paint dry instead. Chris Farris and Rich Mogull make this one useful because they don’t aim for completeness. Instead they cover the “90% of attacks experienced by 90% of organizations using the cloud” . I particularly enjoyed the ‘Why This Matters’ sections which help me feel a little less stupid.

  3. Detecting AI resource-hijacking with Composite Alerts

    If you can get past the magic-alerts-marketing, there are some really interesting details in this incident writeup from Lacework. The assertion is that the threat actor’s objective was “LLMjacking”, based on a variety of API calls made. They describe successful invocations of Ahtonropic Claude models, amongst many other IOCs that are worth reviewing.

Bonus: Gotcha: always use ARNs for S3 SSE-KMS - Aidan Steele explains why it’s important to always specify KMS keys as ARNs rather than aliases applying encryption to S3.

🥗 AWS security blogs

🍛 Reddit threads on r/aws

🧁 IAM permission changes

🍪 API changes

🍹 IAM managed policy changes

Managed Policy changed since last week: 10
  1. AWSOrganizationsReadOnlyAccess
  2. 🚩 AWSProtonDeveloperAccess
  3. 🚩 AWSProtonFullAccess
  4. 🚩 AmazonDataZoneGlueManageAccessRolePolicy
  5. 🚩 AmazonSageMakerModelGovernanceUseAccess
  6. 🚩 AmazonSageMakerModelRegistryFullAccess
  7. AmazonTimestreamReadOnlyAccess
  8. 🚩 CloudWatchApplicationSignalsFullAccess
  9. 🚩 CloudWatchApplicationSignalsReadOnlyAccess
  10. WAFV2LoggingServiceRolePolicy

🔀 Weekly diff

🤖 Powered by MAMIP | 🚩 Sensitive IAM Actions included

☕ CloudFormation resource changes

🎮 Amazon Linux vulnerabilities

No CVE this week 🎉

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.