Monday,
July 29, 2024

๐Ÿฅ– Palette Cleanser

Cloud security is back to normal. I know this because my 70 year old mother has not called me this week to explain how my friends broke everything. Yay! There was some great gossip nonetheless, as Wiz apparently walked away from a $23 billion acquisition offer from Alphabet.

If you are headed to Defcon this year, the Cloud Village has some exceptional talks scheduled August 9-11.

Have feedback about AWS Security Digest? Tell us here.

๐Ÿ“‹ Chef's selections

Bonus: For those that like decoding things but without cool decoder rings, Aidan W Steele (the W is for Winning) gives us a decoder for turning AWS unique IDs into ARNs.

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws


๐Ÿค– Dessert

Dessert is made by robots, for those that enjoy the industrial content.

๐Ÿง IAM permission changes

elasticloadbalancingv2, gamelift, cleanrooms, ssm, ecr, entityresolution, workmail, cleanrooms, cloudtrail, eks, quicksight, resource-explorer-2, connect

๐Ÿช API changes

AWS Clean Rooms Service, AWS IoT SiteWise, AWS Elemental MediaPackage v2, AWS Health Imaging, AWS Clean Rooms Service, AWS Clean Rooms ML, Amazon Connect Service, Amazon Connect Contact Lens, AWS EntityResolution, Amazon Connect Service, Amazon Elastic Compute Cloud, Amazon Kinesis Firehose, AWS Elemental MediaLive, Amazon SageMaker Service, Amazon DataZone, Redshift Serverless

๐Ÿน IAM managed policy changes

AmazonSageMakerCanvasEMRServerlessExecutionRolePolicy, AmazonOpenSearchServerlessServiceRolePolicy, AWSMarketplaceSellerFullAccess, CloudwatchApplicationInsightsServiceLinkedRolePolicy, AmazonDMSVPCManagementRole, AWSResilienceHubAsssessmentExecutionPolicy, AWSBackupOperatorAccess, AmazonSageMakerNotebooksServiceRolePolicy, AmazonConnectSynchronizationServiceRolePolicy, AmazonSageMakerNotebooksServiceRolePolicy, FMSServiceRolePolicy, AWSDataSyncFullAccess, AWSElementalMediaLiveReadOnly, AWSDataExchangeReadOnly

โ˜• CloudFormation resource changes

AWS::CleanRooms::ConfiguredTable, AWS::CleanRooms::ConfiguredTableAssociation, AWS::EntityResolution::MatchingWorkflow, AWS::EntityResolution::SchemaMapping, AWS::CleanRooms::IDMappingTable, AWS::CleanRooms::IdNamespaceAssociation, AWS::WorkSpacesWeb::UserSettings

๐ŸŽฎ Amazon Linux vulnerabilities

CVE-2024-41091, CVE-2024-41090, CVE-2024-41110, CVE-2024-6197, CVE-2024-1975, CVE-2024-4076, CVE-2024-1737