Issue #217

Monday · July 07, 2025

๐Ÿฅ– Palate Cleanser

The internet ghosted us this week.

After giving us content overload last issue, there's been barely a whisper since. The good news is fwd:cloudsec USA talks are live, so there's plenty of interesting content to consume nonetheless.

Apparently, edge network devices have been trying to catch the internet on fire again. This time it's Citrix Netscaler ADC and Netscaler Gateway. I don't know how bad this is, but ReliaQuest has reported "indications of exploitation" in the wild. Maybe these kinds of devices just need a rethink.

Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.

๐Ÿ“‹ Chef's selections

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws


๐Ÿค– Dessert

Every machine-tracked change this week. Nobody else assembles this.

๐Ÿง IAM permission changes

๐Ÿช API changes

๐Ÿน IAM managed policy changes

โ˜• CloudFormation resource changes

๐ŸŽฎ Amazon Linux vulnerabilities

๐Ÿ“บ AWS security bulletins

    No bulletins this week.

๐Ÿšฌ Security documentation changes

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.