Monday,
October 28, 2024

๐Ÿฅ– Palette Cleanser

What is the state of cloud security? Datadog is very glad you asked! Their answer comes complete with pretty moving birds in the header, adding credibility to the data. There's lots of great fodder to copy and paste to your manager in order to convince them of whatever you want. For example, 46% of you savages are still using IAM users, so it must be totes fine to continue. The report includes a technical description of how they got the data at the end, which is a nice touch for the nerds (me).

A lot of awesome protective resources were published this week that deserve their own mention. Travis McPeak from Resourcely teamed up with a bunch of cloud veterans to gift us a huge repository of cloud guardrails. CloudCopilot explained every IAM condition operator in excruciating detail. And we got introductions to two tools: SkyScalpel for combatting IAM obfuscation, and CloudTail for long-term log retention and search.

I somehow missed the SANS CloudSecNext Summit 2024, oops! Luckily, the presentations are up on YouTube.

Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.

๐Ÿ“‹ Chef's selections

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws


๐Ÿค– Dessert

Dessert is made by robots, for those that enjoy the industrial content.

๐Ÿง IAM permission changes

๐Ÿช API changes

๐Ÿน IAM managed policy changes

โ˜• CloudFormation resource changes

๐ŸŽฎ Amazon Linux vulnerabilities

๐Ÿ“บ AWS Security Bulletins

YouTube Twitter LinkedIn