Issue #163

Monday · June 24, 2024

πŸ“‹ Chef's selections

  1. Tales from the cloud trenches: Raiding for AWS vaults, buckets and secrets

    Martin McCloskey takes us inside an attack campaign enumerating secrets, S3 buckets, and S3 Glacier vaults. Lot’s of tactics, techniques, and procedures (TTPs) in this one for those into detection and response.

  2. AWS OIDC Provider Enumeration

    Rami McCarthy took the challenge to do AWS security research to heart and published some code to find which vendors have Github Actions OIDC configured.

  3. AWS’s head of security shares 7 reasons why security will always be Amazon’s top priority

    This article focuses on how Amazon thinks about AI, innovation, and security culture. It reads a little as if it was written for SEO juice but there are some good nuggets in there for security leaders.

πŸ₯— AWS security blogs

🧁 IAM permission changes

πŸͺ API changes

🍹 IAM managed policy changes

Managed Policy changed since last week: 9

  1. AWSApplicationAutoscalingWorkSpacesPoolPolicy
  2. AWSBudgetsReadOnlyAccess
  3. 🚩 AWSConfigServiceRolePolicy
  4. 🚩 AWS_ConfigRole
  5. 🚩 AmazonAthenaFullAccess
  6. AmazonConnectReadOnlyAccess
  7. ComputeOptimizerReadOnlyAccess
  8. ECRTemplateServiceRolePolicy
  9. 🚩 ReadOnlyAccess

πŸ”€ Weekly diff

πŸ€– Powered by MAMIP | 🚩 Sensitive IAM Actions included

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.