Monday,
December 23, 2024

๐Ÿฅ– Palette Cleanser

Greetings festive readers,

What a ride 2024 has been! Today's issue is a special one. We're looking back at all the fun we had this year. We did have fun, didn't we?! New content will be back next week and there will be no interruption to scheduled programming.

The year was more than just content of course, it was defined by some big events and milestones. AWS launched its public vulnerability disclosure program and also made it's previously secret bug bounty, not so secret. The XZ backdoor set the internet on fire for a few weeks and cloud security vendors were at the pointy end of the response. Let's not forget the CUPS bugs. And at the end we got Resource Control Policies and organisational root account management at re:Invent.

Unrelated but important: it might feel like ASD is my baby but I am just the step father. Victor Grenu built AWS Security Digest from the ground up and ran it diligently for many years. In June he agreed to entrust me and Plerion with it going forward. Thank you Victor! None of this would be possible without you. <3

Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.

๐Ÿ“‹ Chef's selections

I put the call out to the community for their highlights and got an overwhelming response. There's not enough room for everything so here is the content that defined the year:

My personal favourites are a little bit different. You may have noticed I have a bias towards attack research. Instead of hiding it, I've gone all in:

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws


๐Ÿค– Dessert

Dessert is made by robots, for those that enjoy the industrial content.

๐Ÿง IAM permission changes

๐Ÿช API changes

๐Ÿน IAM managed policy changes

โ˜• CloudFormation resource changes

๐ŸŽฎ Amazon Linux vulnerabilities

๐Ÿ“บ AWS Security Bulletins

    No bulletins this week.

YouTube Twitter LinkedIn