Security Newsletter - Ransomware to be treated almost as terrorism. Norton will let you mine crypto. Cooperation on browser extension security. • SRE Weekly Issue #273 • 📖 [The CloudSecList] Issue 90 • [tl;dr sec] #86a - The Missing Mobile Security • [tl;dr sec] #86 - Dockerfile Best Practices, Mobile Security • AWS Security Hub adds 16 new controls to its Foundational Security Best Practices standard for enhanced cloud security posture monitoring • Amazon Cognito now supports SMS Sandbox from Amazon SNS • AWS WAF and AWS Shield Advanced are available in Asia Pacific (Osaka) • Amazon Forecast Service - 3 updated methods • Amazon Simple Storage Service - 3 updated methods • AWS S3 Control - 2 updated methods • Auto Scaling - 2 updated methods • Did you know that there are nearly 100 ways data from one AWS account can be shared with another? In this post, I explore, in detail, every method of cross-account access. <a href="https://twitter.com/hashtag/aws" target="_blank">#aws</a> <a href="https://twitter.com/hashtag/cloud" target="_blank">#cloud</a> <a href="https://twitter.com/hashtag/security" target="_blank">#security</a> <a href="https://twitter.com/hashtag/devops" target="_blank">#devops</a> <a href="https://twitter.com/hashtag/infosec" target="_blank">#infosec</a> <a href="https://t.co/uKwJfbm6hN" target="_blank">matthewdf10.medium.com/aws-accounts-a…</a> • Default budget controls is the single most important thing AWS employees could do both for ensuring long-term revenue growth by making it more approachable for beginners that will turn into larger customers AND to help low income groups have opportunities to safely learn. • Ever wanted to retrieve AWS security credentials from the AWS console? (AWS_ACCESS_KEY_ID etc.) Tiny blog post: <a href="https://t.co/DGpugVmee7" target="_blank">blog.christophetd.fr/retrieving-aws…</a> Useful for identity federation when the IdP doesn't support the CLI, or for pentesting if you compromised browser cookies of a target. • This is a cool way of AV scanning EC2s. Instead of an agent (which has performance, stability, and often negative security implications), snapshot the disk, and scan the snapshot instead. • Just updated my blog post comparing various Infrastructure-as-Code security scanning tools with the latest additions of regula and checkov - check it out! <a href="https://t.co/DvnZICMNrk" target="_blank">blog.christophetd.fr/shifting-cloud…</a> Thread ⬇️ • 🔥 Free mobile security class by <a href="https://twitter.com/reyammer" target="_blank">@reyammer</a> * Slides * Recordings * Hands-on reversing and exploitation challenges This is probably one of the best mobile security resources out there, and it's free! Thanks <a href="https://twitter.com/reyammer" target="_blank">@reyammer</a>, super useful 🙏 <a href="https://t.co/BrbL9XEyaL" target="_blank">mobisec.reyammer.io</a> • 📖 Curious what various pen testing firms' reports look like? Check out this repo by <a href="https://twitter.com/juliocesarfort" target="_blank">@juliocesarfort</a> Contains a TON of public reports by consulting firms and academic security groups <a href="https://twitter.com/hashtag/Pentesting" target="_blank">#Pentesting</a> <a href="https://t.co/lKOhBvkoal" target="_blank">github.com/juliocesarfort…</a> • Taking a bit of a break from my technical blog posts to share some thoughts on interviewing for cloud security roles. Feedback is welcome! Please share what kinds of ?s you ask when looking for your next gig. <a href="https://twitter.com/hashtag/Cloud" target="_blank">#Cloud</a> <a href="https://twitter.com/hashtag/Security" target="_blank">#Security</a> <a href="https://twitter.com/hashtag/jobsearch" target="_blank">#jobsearch</a> <a href="https://twitter.com/hashtag/infosecurity" target="_blank">#infosecurity</a> <a href="https://t.co/zatAGaCEL4" target="_blank">matthewdf10.medium.com/questions-to-a…</a> • I have to say I wasn't expecting this level of shade from the GitHub API this morning. • I started dating my hot crush from grad school (5+ years later!) and I’m pretty sure I can die from happiness right now • The recent "all the ways to run containers on AWS" posts have left me super confused, so I made this flowchart. It's probably also wrong. • Flashcards to learn AWS skills • How to Build an Online Store with React, AWS, and Stripe • Mysterious AWS NLB timeouts in Kubernetes • AWS VPC for Software Engineers • Kubernetes Goat - Designed to be an intentionally vulnerable cluster environment to learn and practice Kubernetes security • New CVE database that visualizes CVEs and shows exploit price and eco impact • Want to find out about Check Point Cloud Guard? • Sumo Logic Extends AWS Alliance to Launch SIEM Service - Security Boulevard • Bringing innovation and security to government missions with AWS GovCloud (US) - FedScoop • Sumo Logic and AWS Collaborate to Transform Security for Multi-Cloud and Hybrid Threat Protection - GlobeNewswire
7
Monday June, 2021

AWS Security Hub adds 16 new controls to its Foundational Security Best Practices standard for enhanced cloud security posture monitoring

Jun 4
AWS Security Hub has released 16 new controls for its Foundational Security Best Practice standardand, nbsp;to enhance customers' cloud security posture monitoring. These controls conduct fully automatic checks against security best practices for Amazon API Gateway (APIGateway.2, APIGateway.3), AWS Elastic Beanstalk (ElasticBeanstalk.1, ElasticBeanstalk.2), Amazon RDS (RDS.12, RDS.13, RDS.14), Amazon EC2 …

Amazon Cognito now supports SMS Sandbox from Amazon SNS

Jun 2
Amazon Cognito now supports SMS Sandbox in Amazon SNS. Amazon Cognito makes it easy to add authentication, authorization, and user management to your web and mobile apps. Amazon Cognito scales to millions of users and supports sign-in with social identity providers, such as Apple, Facebook, Google, and Amazon, and enterprise …

AWS WAF and AWS Shield Advanced are available in Asia Pacific (Osaka)

Jun 1
Starting today, AWS WAF and AWS Shield Advanced are available in Asia Pacific (Osaka).

Amazon Forecast Service - 3 updated methods

Jun 3
Added optional field AutoMLOverrideStrategy to CreatePredictor API that allows users to customize AutoML strategy. If provided in CreatePredictor request, this field is visible in DescribePredictor and GetAccuracyMetrics responses.

Amazon Simple Storage Service - 3 updated methods

Jun 3
S3 Inventory now supports Bucket Key Status

AWS S3 Control - 2 updated methods

Jun 3
S3 Inventory now supports Bucket Key Status

Auto Scaling - 2 updated methods

Jun 2
You can now launch EC2 instances with GP3 volumes when using Auto Scaling groups with Launch Configurations
matthewdfuller
Matt Fuller @matthewdfuller

Did you know that there are nearly 100 ways data from one AWS account can be shared with another? In this post, I explore, in detail, every method of cross-account access.
#aws #cloud #security #devops #infosec
matthewdf10.medium.com/aws-accounts-a…

142Jun 02 · 2:03 AM
0xdabbad00
Scott Piper @0xdabbad00

Default budget controls is the single most important thing AWS employees could do both for ensuring long-term revenue growth by making it more approachable for beginners that will turn into larger customers AND to help low income groups have opportunities to safely learn.

alexwlchan
Alex Chan @alexwlchan

Hey friends,

I have a panicked student in my DMs who’s accidentally racked up an $8k AWS bill.

My suggestion of “talk to Support” is no good—apparently they won’t issue a billing adjustment. Anybody got better ideas, or know someone at AWS who can help them out?

RT for reach?

32May 31 · 8:34 PM
christophetd
Christophe @christophetd

Ever wanted to retrieve AWS security credentials from the AWS console? (AWS_ACCESS_KEY_ID etc.)

Tiny blog post: blog.christophetd.fr/retrieving-aws…

Useful for identity federation when the IdP doesn't support the CLI, or for pentesting if you compromised browser cookies of a target.

54Jun 05 · 7:30 PM
0xdabbad00
Scott Piper @0xdabbad00

This is a cool way of AV scanning EC2s. Instead of an agent (which has performance, stability, and often negative security implications), snapshot the disk, and scan the snapshot instead.

swagitda_
Kelly Shortridge @swagitda_

Introducing Patrolaroid, a malware scanner for AWS instances that doesn't yeet around your prod.

@rpetrich & I made it OSS so ppl don't have to deploy sketchy security tools in prod just for basic coverage of malware, miners, toolkits, backdoors, etc.

github.com/rpetrich/patro…

18Jun 04 · 3:26 PM
christophetd
Christophe @christophetd

Just updated my blog post comparing various Infrastructure-as-Code security scanning tools with the latest additions of regula and checkov - check it out!

blog.christophetd.fr/shifting-cloud…

Thread ⬇️

21Jun 02 · 11:07 PM
clintgibler
Clint Gibler @clintgibler

🔥 Free mobile security class by @reyammer

* Slides
* Recordings
* Hands-on reversing and exploitation challenges

This is probably one of the best mobile security resources out there, and it's free!

Thanks @reyammer, super useful 🙏

mobisec.reyammer.io

23Jun 02 · 5:00 PM
clintgibler
Clint Gibler @clintgibler

📖 Curious what various pen testing firms' reports look like?

Check out this repo by @juliocesarfort

Contains a TON of public reports by consulting firms and academic security groups

#Pentesting

github.com/juliocesarfort…

21Jun 02 · 9:00 PM
matthewdfuller
Matt Fuller @matthewdfuller

Taking a bit of a break from my technical blog posts to share some thoughts on interviewing for cloud security roles. Feedback is welcome! Please share what kinds of ?s you ask when looking for your next gig.
#Cloud #Security #jobsearch #infosecurity
matthewdf10.medium.com/questions-to-a…

17Jun 01 · 3:33 AM
__steele
Aidan W Steele @__steele

I have to say I wasn't expecting this level of shade from the GitHub API this morning.

4Jun 07 · 2:21 AM
kmcquade3
Kinnaird McQuade💥☁️ @kmcquade3

I started dating my hot crush from grad school (5+ years later!) and I’m pretty sure I can die from happiness right now

0Jun 03 · 4:15 PM

buymeacoffee