Security Newsletter - New Spectre-like attacks. Ransomware takes down pipeline. Minimal issue. • SRE Weekly Issue #269 • 📖 [The CloudSecList] Issue 86 • [tl;dr sec] #82 - Supply Chain Security, Career Resources • Introducing IAM Access Control for Apache Kafka on Amazon MSK • Managed Streaming for Kafka - 4 updated methods • Amazon Import/Export Snowball - 3 new 7 updated methods • Amazon Simple Systems Manager (SSM) - 6 updated methods • Amazon Kinesis Analytics - 1 new 8 updated methods • How to monitor expirations of imported certificates in AWS Certificate Manager (ACM) • Nine additional AWS cloud service offerings authorized by DISA • Use ACM Private CA for Amazon API Gateway Mutual TLS • IAM makes it easier for you to manage permissions for AWS services accessing your resources • IAM 10th Anniversary: Top Recommendations for Working with IAM from Our AWS Heroes – Part 1 | Amazon Web Services • Top Recommendations for Working with IAM from Our AWS Heroes – Part 3: Permissions Boundaries and Conditions | Amazon Web Services • “We’ve recently upgraded our security, please create a new password” No, you got hacked and don’t want to be honest about it 🙄 • 🎂Y’all might have heard it’s IAM 10th Birthday. 🎂IAM is officially in the double digits. There are so many reasons to celebrate IAM on it’s special day. Here is my list. (1/11) • <a href="https://twitter.com/hashtag/awswishlist" target="_blank">#awswishlist</a> Stop using IAM user access keys in blog posts. • New AWS architecture icons day 🧑‍🎨 Available at <a href="https://t.co/49N1gbfLc0" target="_blank">aws.amazon.com/architecture/i…</a> • 🔥 New from <a href="https://twitter.com/pdiscoveryio" target="_blank">@pdiscoveryio</a> 🛠️Interactsh: Open source out-of-band testing tool * Can emulate HTTP, DNS, &amp; SMTP w/ wildcards enabled. Nuclei integration coming <a href="https://t.co/RgafDDdNK4" target="_blank">blog.projectdiscovery.io/interactsh-rel…</a> 🏃Exploiting Race conditions w/ <a href="https://twitter.com/pdnuclei" target="_blank">@pdnuclei</a> <a href="https://t.co/PKtKp3NcI5" target="_blank">blog.projectdiscovery.io/exploiting-rac…</a> <a href="https://twitter.com/hashtag/bugbountytips" target="_blank">#bugbountytips</a> <a href="https://twitter.com/hashtag/WebSecurity" target="_blank">#WebSecurity</a> • Happy 10th birthday, AWS IAM! Thanks to all of the team members over the years that contributed, and thanks to all of the AWS customers who have used it and provided feedback! <a href="https://t.co/qukOP7HQcw" target="_blank">aws.amazon.com/blogs/aws/happ…</a> <a href="https://twitter.com/AWSIdentity" target="_blank">@AWSIdentity</a> Looking forward to the next 10... • A few wks ago I started researching all the ways data can be shared between AWS accts as part of a post I'm writing. 2 wks later and I'm still discovering new ways. Suffice it to say - the security "boundary" that <a href="https://twitter.com/hashtag/AWS" target="_blank">#AWS</a> accounts offer is ridiculous easy to break. <a href="https://twitter.com/hashtag/cloud" target="_blank">#cloud</a> <a href="https://twitter.com/hashtag/security" target="_blank">#security</a> • Ten years ago, AWS Identity and Access Management (IAM) was born. Reflections on what's changed in the last decade: <a href="https://t.co/nF0ID0P9la" target="_blank">linkedin.com/pulse/decade-s…</a> <a href="https://twitter.com/AWSIdentity" target="_blank">@AWSIdentity</a> • The existence of aws:PrincipalIsAWSService, aws:ViaAWSService, aws:CalledVia, and related condition keys is chaos. • Moar Dependency Confusion Resources 🧵 ⚒️ DazedAndConfused: helps determine your exposure Currently works on 12+ types of dependency files (more than any other tool I've seen) Also has support for scanning GitHub and GitLab servers <a href="https://t.co/H8XtwVBu9S" target="_blank">github.com/salesforce/Daz…</a> • VPC Peering traffic within the same AZ is now free 🎉 • Please fix the AWS Free Tier before somebody gets hurt • 👍🏻 AWS announces a price reduction for Amazon Managed Service for Prometheus (AMP) by up to 84% • Introducing CloudFront Functions – Run Your Code at the Edge with Low Latency at Any Scale • A New AWS SDK for Rust – Alpha Launch • Almost 8 million BGP route leaks and more than 7 million BGP hijacks in Q1 2021 alone • Incident response playbooks • Big Data encryption or other security tools in the cloud • castLabs announces support for AWS for Media & Entertainment initiative - PRNewswire • Sysdig adds detailed audit logs for runtime detection and response for AWS Fargate - Help Net Security - Help Net Security • Singapore security ISV Horangi hits the AWS Marketplace - Channel Asia Singapore
10
Monday May, 2021

Best of breed Sec Newsletters:

Introducing IAM Access Control for Apache Kafka on Amazon MSK

May 6
Today we announced AWS Identity and Access Management (IAM) Access Control for Amazon MSK. IAM Access Control is a security option offered at no additional cost that simplifies cluster authentication and Apache Kafka API authorization using IAM role or user policies to control access. By using IAM Access Control, customers …

Managed Streaming for Kafka - 4 updated methods

May 6
IAM Access Control for Amazon MSK enables you to create clusters that use IAM to authenticate clients and to allow or deny Apache Kafka actions for those clients.

Amazon Import/Export Snowball - 3 new 7 updated methods

May 6
AWS Snow Family adds APIs for ordering and managing Snow jobs with long term pricing

Amazon Simple Systems Manager (SSM) - 6 updated methods

May 6
SSM feature release - ChangeCalendar integration with StateManager.

Amazon Kinesis Analytics - 1 new 8 updated methods

May 5
Amazon Kinesis Analytics now supports RollbackApplication for Apache Flink applications to revert the application to the previous running version

How to monitor expirations of imported certificates in AWS Certificate Manager (ACM)

Dmitry KaganskyMay 7
Certificates are vital to maintaining trust and providing encryption to internal or external facing infrastructure and applications. AWS Certificate Manager (ACM) provides certificate services to any workload that requires them. Although ACM provides managed renewals that automatically renew certificates in most cases, there are exceptions, such as imported certs, where …

Nine additional AWS cloud service offerings authorized by DISA

Tyler HardingMay 6
I’m excited to share that the Defense Information Systems Agency (DISA) has authorized three additional Amazon Web Services (AWS) services at Impact Level (IL) 4 and IL 5 in the AWS GovCloud (US) Regions, as well as five additional AWS services and one feature at IL 6 in the AWS …

Use ACM Private CA for Amazon API Gateway Mutual TLS

Tracy PierceMay 5
Last year Amazon API Gateway announced certificate-based mutual Transport Layer Security (TLS) authentication. Mutual TLS (mTLS) authenticates the server to the client, and requests the client to send an X.509 certificate to prove its identity as well. This way, both parties are authenticated to each other. In a previous post, …

IAM makes it easier for you to manage permissions for AWS services accessing your resources

Ilya EpshteynMay 4
Amazon Web Services (AWS) customers are storing an unprecedented amount of data on AWS for a range of use cases, including data lakes and analytics, machine learning, and enterprise applications. Customers secure their data by implementing data security controls including identity and access management, network security, and encryption. For non-public, …
kmcquade3
Kinnaird McQuade💥☁️ @kmcquade3

“We’ve recently upgraded our security, please create a new password”

No, you got hacked and don’t want to be honest about it 🙄

18May 10 · 3:46 PM
bjohnso5y
Brigid Johnson @bjohnso5y

🎂Y’all might have heard it’s IAM 10th Birthday. 🎂IAM is officially in the double digits. There are so many reasons to celebrate IAM on it’s special day. Here is my list. (1/11)

21May 04 · 2:32 AM
0xdabbad00
Scott Piper @0xdabbad00

#awswishlist Stop using IAM user access keys in blog posts.

AWSBlogs
AWS Blogs @AWSBlogs

New Developer post by iliana etaoin:

A New AWS SDK for Rust – Alpha Launch
aws.amazon.com/blogs/develope…

13May 07 · 11:53 PM
iann0036
Ian Mckay @iann0036

New AWS architecture icons day 🧑‍🎨

Available at aws.amazon.com/architecture/i…

18May 06 · 1:22 AM
clintgibler
Clint Gibler @clintgibler

🔥 New from @pdiscoveryio

🛠️Interactsh: Open source out-of-band testing tool
* Can emulate HTTP, DNS, & SMTP w/ wildcards enabled. Nuclei integration coming
blog.projectdiscovery.io/interactsh-rel…

🏃Exploiting Race conditions w/ @pdnuclei
blog.projectdiscovery.io/exploiting-rac…

#bugbountytips #WebSecurity

21May 04 · 5:00 PM
jim_scharf
Jim Scharf @jim_scharf

Happy 10th birthday, AWS IAM! Thanks to all of the team members over the years that contributed, and thanks to all of the AWS customers who have used it and provided feedback! aws.amazon.com/blogs/aws/happ… @AWSIdentity Looking forward to the next 10...

13May 03 · 6:55 PM
matthewdfuller
Matt Fuller @matthewdfuller

A few wks ago I started researching all the ways data can be shared between AWS accts as part of a post I'm writing. 2 wks later and I'm still discovering new ways. Suffice it to say - the security "boundary" that #AWS accounts offer is ridiculous easy to break. #cloud #security

7May 09 · 8:56 PM
jim_scharf
Jim Scharf @jim_scharf

Ten years ago, AWS Identity and Access Management (IAM) was born. Reflections on what's changed in the last decade: linkedin.com/pulse/decade-s… @AWSIdentity

9May 03 · 7:13 PM
0xdabbad00
Scott Piper @0xdabbad00

The existence of aws:PrincipalIsAWSService, aws:ViaAWSService, aws:CalledVia, and related condition keys is chaos.

AWSBlogUnreal
AWS Blog Unofficial. @AWSBlogUnreal

The AWS Security, Identity & Compliance Blog #AWSSecurity
aws.amazon.com/blogs/security…
By: Ilya Epshteyn and Harsha Sharma

6May 04 · 6:32 PM
clintgibler
Clint Gibler @clintgibler

Moar Dependency Confusion Resources 🧵

⚒️ DazedAndConfused: helps determine your exposure

Currently works on 12+ types of dependency files (more than any other tool I've seen)

Also has support for scanning GitHub and GitLab servers

github.com/salesforce/Daz…

13May 05 · 5:00 PM

Big Data encryption or other security tools in the cloud

What tools do companies use for Big Data protection in the cloud? We want securely collect, aggregate and analyze (using Apache Spark) text files and video streams from our end users. What is the best way to protect their data without degrading cloud speed? Do any tools enable arbitrary access, …