Issue #212

Monday · June 02, 2025

๐Ÿฅ– Palate Cleanser

Was it a quiet week, or was it just quiet in Bali?

If you also happen to have some quiet time, consider submitting to the fwd:cloudsec Europe CFP. It's an awesome conference, and they want talks from any practitioner who is responsible for securing a cloud service or service provider.

Have a wonderful week, my lovelies.

Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.

๐Ÿ“‹ Chef's selections

  • CloudTrail Logging Evasion: Where Policyโ€ฏSize Matters by Abian Morina

    Simple hacking is the best hacking. What happens if you stick a lot of whitespace in a request to the AWS API? Sometimes maybe good things, sometimes maybe bad things. Abian provides precision about how whitespace is treated in IAM policies and how much whitespace is required to drop a policy from CloudTrail in an iam:CreatePolicy API call. This issue won't be fixed for some time, so it's worth being on the lookout for "requestParameters too large" in CloudTrail.

  • Storm-0558 and the Dangers of Cross-Tenant Token Forgery by Damian Archer

    Damian analyzed the token abuse tactics used by Storm-0558 to forge tokens to access Microsoft OWA and Outlook.com. He turned all the lessons into this post, full of guidelines you can implement on top of any cloud provider to stay safe.

  • Automatically prioritize security issues from different tools with an LLM by Daniel Grzelak

    Bad (or no) prioritization is a killer of security teams. This is a cool little experiment in using AWS Bedrock to prioritize security issues of different shapes and sizes, from disparate tools. It comes with Python code for three different prioritization approaches that have their own strengths and weaknesses, so you can adapt them to your environment.

Bonus: SecretsManager Harvesting in AWS

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws


๐Ÿค– Dessert

Every machine-tracked change this week. Nobody else assembles this.

๐Ÿง IAM permission changes

๐Ÿช API changes

๐Ÿน IAM managed policy changes

โ˜• CloudFormation resource changes

    No resource updates this week.

๐ŸŽฎ Amazon Linux vulnerabilities

๐Ÿ“บ AWS security bulletins

๐Ÿšฌ Security documentation changes

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.