
September 30, 2024
๐ฅ Palette Cleanser
AWS re:Invent season has started ahead of the 2 December Las Vegas scheduled date. There are already 187 security-related sessions in the catalog. I wonder if the stream of service deprecations will continue before then?
Speaking of conferences, there's been a lot of chatter and praise for the fwd:cloudsec Europe keynote. With a title like, "How to 10X Your Cloud Security (Without the Series D)", it's hardly a surprise. If you can't sit through the full 51min version, Rami Mac (that's his rapper name) comes in hot with this week's summary video for his own keynote. Is this cloud security Inception?
I should probably talk about the CUPS vulnerabilities but I really don't want to. They feel like a bit of a nothing burger for cloud environments. Unrelated, our cloud hacking heroes at Wiz found a cool vulnerability in NVIDIA Container Toolkit. At least I'm guessing it's cool because the details are not very detailed. The real world impact of this also appears limited. Perhaps a smart reader can share some insights about either issue? Let's get you a quote in the next issue!
Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.
๐ Chef's selections
-
Redefining CNAPP: A Complete Guide To the Future of Cloud Security by Francis Odum & James Berthoty
It was bound to happen one day, and that day is today. We're going FULL CNAPP. You're never going to agree fully with a report like this but I haven't seen an analysis of the cloud security market this thorough and well-reasoned before. The authors don't hold back: "CNAPP has created a crappy version of too many standalone products and is at a serious breaking point."
One minor gripe - can we please stop mis-using "detection" in the context of finding misconfigurations and vulnerabilities? Think NIST NIST Cybersecurity Framework functions - govern, identify, protect, detect, respond, recover. Detections are for bad things that have happened, not for things that could enable bad things to happen in the future.
If you're in the process of trying to get the most out of your CNAPP, Naman Sogani just published part 2 of his implementation guide.
-
Gaining AWS Persistence by Updating a SAML Identity Provider by Adan รlvarez
Finding creative ways to backdoor AWS accounts is a niche passion for Adan (and me). This particular approach of switching out metadata to point to an attacker controlled identity provider has limited real world applications because after changing the SAML metadata, legitimate users wonโt be able to login via SSO. However, it's still worth reading in order to internalise the impact of frivolously giving out "UpdateSAMLProvider" permissions.
-
Tracking cloud-fluent threat actors - Part one: Atomic cloud IOCs by Merav Bar & Amitai Cohen
This is a very consumable primer on what defenders and detection engineers need to care about in terms of cloud indicators of compromise. The authors do an excellent job describing why each indicator is important, giving examples of how they used it to track past threat actors, and giving some practical advice for using it yourself. Oh, and the post comes with an open source indicator database.
If you like tracking threat actors, you'll probably also enjoy reading how Threat Actors leverage Docker Swarm and Kubernetes to mine cryptocurrency at scale.
๐ฅ AWS security blogs
- Centrally detect and investigate security findings with AWS Organizations integrations by Nivedita Tripathi
- Securing Your Software Supply Chain with Amazon CodeCatalyst and Amazon Inspector by Piyush Mattoo
- Introducing security group referencing for AWS Transit Gateway by Gerardo Vazquez
- Mitigating inadvertent IPv6 prefix advertisement with AWS automation by John Dwyer
- Getting drugs to market faster through better health data management on AWS by Nora O'Sullivan
- New courses and certification updates from AWS Training and Certification in September 2024 by Training and Certification Blog Editor
๐ Reddit threads on r/aws
๐ค Dessert
Dessert is made by robots, for those that enjoy the industrial content.
๐ง IAM permission changes
๐ช API changes
- Amazon Connect Customer Profiles
- Amazon QuickSight
- Amazon Simple Email Service
- AWS Chatbot
- AWS Organizations
- Amazon SageMaker Service
- Amazon Kinesis
- Amazon Pinpoint SMS Voice V2
- Amazon SageMaker Service
- Amazon Athena
- Amazon Elastic Compute Cloud
- EMR Serverless
- AWS Glue
- Amazon Relational Database Service
- AWS Resource Explorer
๐น IAM managed policy changes
- AWSBackupServiceRolePolicyForBackup
- AWSBackupServiceRolePolicyForBackup
- AWSBackupFullAccess
- QAppsServiceRolePolicy
- AWSSSOMasterAccountAdministrator
- AmazonEC2RolePolicyForLaunchWizard
- AmazonConnectSynchronizationServiceRolePolicy
- AWSAuditManagerServiceRolePolicy
- AmazonSNSFullAccess
- AmazonSNSReadOnlyAccess