Monday,
April 28, 2025

๐Ÿฅ– Palette Cleanser

Welcome back cloud security nerds to another episode of your favorite AWS Security newsletter.

The whole point of this cloud security stuff is to prevent us and our employers getting pwned, and if we do get pwned, make it less bad. So each year many of us eagerly wait for the Verizon Data Breach Investigations Report to give us real-world data on actual breaches. The wait is over for 2025.

If you are still running vendor security appliances in the cloud, this quote should really scare you: "The exploitation of vulnerabilities has seen another year of growth as an initial access vector for breaches, reaching 20%. This value approaches that of credential abuse, which is still the most common vector. This was an increase of 34% in relation to last yearโ€™s report and was supported, in part, by zeroday exploits targeting edge devices and virtual private networks (VPNs). The percentage of edge devices and VPNs as a target on our exploitation of vulnerabilities action was 22%, and it grew almost eight-fold from the 3% found in last yearโ€™s report."

Finally, this is not a political podcast. Probably because it isn't a podcast and I don't have the energy for politics. I have to admit, Chris Farris slapped me around a little this week with his very thought-provoking post on threat modelling cloud service providers in an era where we can no longer take for granted that the US government is a benevolent and consistent actor. Forget the names and labels that may trigger tribal reactions and consider, does your organization need to manage new risks in the cloud?

Enjoy the virtual food <3

Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.

๐Ÿ“‹ Chef's selections

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws


๐Ÿ’ธ Sponsor shoutout

Pleri is your AI-powered teammate built to boost your cloud security team โ€” faster reactions, smarter actions, no extra headcount. Meet Pleri and see her in action.


๐Ÿค– Dessert

Dessert is made by robots, for those that enjoy the industrial content.

๐Ÿง IAM permission changes

๐Ÿช API changes

๐Ÿน IAM managed policy changes

โ˜• CloudFormation resource changes

    No resource updates this week.

๐ŸŽฎ Amazon Linux vulnerabilities

๐Ÿ“บ AWS security bulletins

YouTube Twitter LinkedIn