
May 26, 2025
🥖 Palette Cleanser
Om Suwastiastu 🏝️ That's Balinese for 'may you (and your AWS account) be blessed and protected.'
Last week there was a lot of talk of vulnerability-free containers. This week is totally different! Docker released their *hardened* containers. I wonder what kind of containers next week will bring?
I'm really enjoying how much AWS has been listening to their community lately, slowly putting what-should-be-unnecessary projects to bed. This week they launched an end-of-support announcements page that tracks service changes and deprecations, services closing access to new customers, services announcing end of support, and services and features reaching end of support. Now if we could get that in a machine consumable form like RSS, that would be lovely. <3
Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.
📋 Chef's selections
-
Root in prod: The most important security analysis you will never do on your AWS accounts by Daniel Grzelak
I don't like the author but the content is great. Trust relationships within and between AWS accounts are notoriously underappreciated as a risk and very difficult to track. There aren't many tools to help. In this article I give you all the code you need to do it yourself, make pretty graphs, and really dig into who/what could nuke your business.
-
Setting Up a Cloud Security Roadmap for Your Startup by Chandrapal Badshah
Chandra has been helping startups with AWS security for a while now. He's learned a lot along the way and turned his advice into this guest post. He reviewed 3 of the open source roadmap options and who they might be best for. A point he makes towards the end stands out: these roadmaps are great starting points but if you have time, "be opinionated when creating your roadmap" and align it with your business.
-
Using the AWS CLI and Securing CloudShell by Rich Mogull
I can't remember the last time Rich didn't release a new AWS security tutorial in a given week. His posts could be in ASD every week. This time he explains how to use AWS CloudShell as a secure, browser-based home for the AWS CLI. The hidden metadata-service credentials were news to me! The walkthrough then has you assume roles into other accounts, run CLI commands, download files, and inspect CloudTrail so you can both operate and monitor CloudShell safely.
Bonusii:
🥗 AWS security blogs
- 📣 AWS Organizations now supports Internet Protocol Version 6 (IPv6)
- 📣 Amazon Inspector enhances container security by mapping ECR images to running containers
- Shiny Shoe launches Monster Train 2 on AWS by Caleb Cecil
- Streamline scalable AI governance with Domino in AWS Marketplace by James Yi
- How to secure your instances with multi-factor authentication by Sangavi P
- Digital sovereignty to take center stage: What to expect at AWS Summit Hamburg 2025 by Lena Niebling
- University of British Columbia Cloud Innovation Centre: Prototyping generative AI solutions using AWS by Christian Castro
- How public safety agencies can meet AI data security requirements by Rhea Lingaiah
- How to automate incident response for Amazon EKS on Amazon EC2 by Jonathan Nguyen
🍛 Reddit threads on r/aws
-
No threads this week.
💸 Sponsor shoutout
Pleri is your AI-powered teammate built to boost your cloud security team — faster reactions, smarter actions, no extra headcount. Meet Pleri and see her in action.
🤖 Dessert
Dessert is made by robots, for those that enjoy the industrial content.
🧁 IAM permission changes
🍪 API changes
- Amazon Elastic Compute Cloud
- Security Incident Response
- Amazon Prometheus Service
- Amazon Aurora DSQL
- AWS Glue
- Agents for Amazon Bedrock Runtime
- Amazon CloudWatch
- Amazon Elastic Compute Cloud
- Amazon Elastic Compute Cloud
- AWS Glue
- Inspector2
- CloudWatch Observability Access Manager
- Amazon Relational Database Service
- Amazon Elastic Compute Cloud
- AWS Elemental MediaPackage v2
🍹 IAM managed policy changes
- AmazonConnectServiceLinkedRolePolicy
- AWSConfigServiceRolePolicy
- AWS_ConfigRole
- AmazonDataZoneFullAccess
- AmazonPrometheusConsoleFullAccess
- SageMakerStudioFullAccess
- AmazonDynamoDBFullAccess_v2
- AWSQuickSightSecretsManagerWriteAccess
- AWSBackupFullAccess
- AWSBackupOperatorAccess
- AWSBackupServiceLinkedRolePolicyForBackup
- AWSBackupServiceRolePolicyForBackup
- AWSBackupServiceRolePolicyForRestores
- AmazonAuroraDSQLConsoleFullAccess
- AmazonAuroraDSQLFullAccess
- FMSServiceRolePolicy
- AWSDataSyncFullAccess
- CloudWatchLogsFullAccess
- CloudWatchLogsReadOnlyAccess
- EC2InstanceProfileForImageBuilder
- AWSPrivateCAConnectorForKubernetesPolicy
- ROSAImageRegistryOperatorPolicy
☕ CloudFormation resource changes
🎮 Amazon Linux vulnerabilities
📺 AWS security bulletins
-
No bulletins this week.
🚬 Security documentation changes
- amazonq Documentation Update
- amazonq Documentation Update
- appsync Documentation Update
- athena Documentation Update
- bedrock Documentation Update
- connect Documentation Update
- connect Documentation Update
- connect Documentation Update
- datazone Documentation Update
- datazone Documentation Update
- dcv Documentation Update
- dcv Documentation Update
- eks Documentation Update
- eks Documentation Update
- eks Documentation Update
- eks Documentation Update
- eks Documentation Update
- eks Documentation Update
- eks Documentation Update
- eks Documentation Update
- managedservices Documentation Update
- organizations Documentation Update
- privateca Documentation Update
- rosa Documentation Update
- systems-manager Documentation Update
- verified-access Documentation Update
- waf Documentation Update
- wickr Documentation Update
- wickr Documentation Update
- amazonq Documentation Update
- amazonq Documentation Update
- amazonq Documentation Update
- amazonq Documentation Update
- amazonq Documentation Update
- aurora-dsql Documentation Update
- clean-rooms Documentation Update
- cli Documentation Update
- cloudshell Documentation Update
- cognito Documentation Update
- datasync Documentation Update
- datasync Documentation Update
- dms Documentation Update
- dms Documentation Update
- eks Documentation Update
- eks Documentation Update
- elasticloadbalancing Documentation Update
- emr Documentation Update
- glue Documentation Update
- glue Documentation Update
- govcloud-us Documentation Update