Monday,
September 30, 2024

๐Ÿฅ– Palette Cleanser

AWS re:Invent season has started ahead of the 2 December Las Vegas scheduled date. There are already 187 security-related sessions in the catalog. I wonder if the stream of service deprecations will continue before then?

Speaking of conferences, there's been a lot of chatter and praise for the fwd:cloudsec Europe keynote. With a title like, "How to 10X Your Cloud Security (Without the Series D)", it's hardly a surprise. If you can't sit through the full 51min version, Rami Mac (that's his rapper name) comes in hot with this week's summary video for his own keynote. Is this cloud security Inception?

I should probably talk about the CUPS vulnerabilities but I really don't want to. They feel like a bit of a nothing burger for cloud environments. Unrelated, our cloud hacking heroes at Wiz found a cool vulnerability in NVIDIA Container Toolkit. At least I'm guessing it's cool because the details are not very detailed. The real world impact of this also appears limited. Perhaps a smart reader can share some insights about either issue? Let's get you a quote in the next issue!

Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.

๐Ÿ“‹ Chef's selections

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws


๐Ÿค– Dessert

Dessert is made by robots, for those that enjoy the industrial content.

๐Ÿง IAM permission changes

๐Ÿช API changes

๐Ÿน IAM managed policy changes

โ˜• CloudFormation resource changes

๐ŸŽฎ Amazon Linux vulnerabilities

YouTube Twitter LinkedIn