Monday,
June 23, 2025

๐Ÿฅ– Palette Cleanser

It was AWS security Christmas last week, and boy did Santa deliver.

In case my metaphors failed to land, Santa is AWS and Christmas is re:Inforce. I was absolutely giddy about the announcements like never before. The keynote from CISO Amy Herzog captures almost everything. For readers, there's an endless stream of highlight content. If you want to catch a session, this repo has a summary and links to all 163 talks.

If it wasn't clear before, it should be clear now: AWS is making a play for the $10B+ CNAPP market, launching or improving many of the features that have become table stakes in products like Wiz and my employer, Plerion. The building blocks are now pretty awesome, but I still can't see how they build the kind of user experience necessary to compete while being stuck in AWS Management Console hell.

My favorites:

Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.

๐Ÿ“‹ Chef's selections

  • Revoking access to IAM Roles Anywhere using open-source private CA by Paul Schwarzenberger

    Paul walks through setting up IAM Roles Anywhere with Smallstepโ€™s open-source CA, then shows how to shut it all down if something goes sideways. He demos certificate revocation via a custom CRL URL in the trust anchor, effectively killing access without waiting for cert expiration. If youโ€™re rolling your own CA, youโ€™d better also roll a plan to take access back fast.

  • Getting Started with CloudTrail Security Queries by Rich Mogull

    How do you use Amazon Athena to find high-risk events in CloudTrail? Rich is glad you asked. He explains how to query tables, filter actions, resources and identities, and pivot on request and response fields to analyze an incident quickly.

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws


๐Ÿ’ธ Sponsor shoutout

Pleri is your AI-powered teammate built to boost your cloud security team โ€” faster reactions, smarter actions, no extra headcount. Meet Pleri and see her in action.


๐Ÿค– Dessert

Dessert is made by robots, for those that enjoy the industrial content.

๐Ÿง IAM permission changes

๐Ÿช API changes

๐Ÿน IAM managed policy changes

โ˜• CloudFormation resource changes

๐ŸŽฎ Amazon Linux vulnerabilities

๐Ÿ“บ AWS security bulletins

    No bulletins this week.

๐Ÿšฌ Security documentation changes

YouTube Twitter LinkedIn